<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Nelson Lopes]]></title><description><![CDATA[Hands-on technical content from an IT Director]]></description><link>https://newsletter.nelsonlopes.net</link><image><url>https://substackcdn.com/image/fetch/$s_!Og9Z!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F000067e1-406c-4d89-b47d-e728c6733770_400x400.png</url><title>Nelson Lopes</title><link>https://newsletter.nelsonlopes.net</link></image><generator>Substack</generator><lastBuildDate>Thu, 11 Jun 2026 18:06:06 GMT</lastBuildDate><atom:link href="https://newsletter.nelsonlopes.net/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Nelson Lopes]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[lopesnelson@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[lopesnelson@substack.com]]></itunes:email><itunes:name><![CDATA[Nelson Lopes]]></itunes:name></itunes:owner><itunes:author><![CDATA[Nelson Lopes]]></itunes:author><googleplay:owner><![CDATA[lopesnelson@substack.com]]></googleplay:owner><googleplay:email><![CDATA[lopesnelson@substack.com]]></googleplay:email><googleplay:author><![CDATA[Nelson Lopes]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Cybersecurity Guide for Parents and Guardians]]></title><description><![CDATA[Practical Steps to Protect Your Children Online]]></description><link>https://newsletter.nelsonlopes.net/p/cybersecurity-guide-for-parents-and-guardians</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/cybersecurity-guide-for-parents-and-guardians</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 09 Jun 2026 08:02:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/youtube/w_728,c_limit/1DpPgZ47RrM" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Unlike when we were the age our children are now, today&#8217;s children are increasingly exposed to technology, which makes it very important for Parents and other Guardians to monitor their online activity. They are young, with little experience, and therefore are not prepared to identify and understand certain situations that may be harmful to them when they use the Internet. This Guide for Parents and Guardians is intended to serve as guidance for what I consider to be the basic precautions.</p><p>Parents and Guardians themselves sometimes fail to recognize some of the dangers, so it is imperative that they acknowledge the importance of staying informed and up to date. The worst thing you can do is to think that it only happens to others. Prepared Parents and Guardians will better prepare their children and dependents for a future that, in all likelihood, will be increasingly technological, regardless of their interests, wishes, and professions.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Applying all the security recommendations can be an extensive and complex task, but don&#8217;t be alarmed. Start somewhere. Cybersecurity should be understood as something continuous and not a one-off action at a particular moment in time. So, don&#8217;t try to apply all the recommendations at once; instead, make this article (and others on this blog) a reference that you return to from time to time in order to improve your online posture.</p><h2>Start by Raising Awareness in Your Children</h2><p>Recognize that the human factor is the weakest one, as demonstrated by the various companies that invest thousands or millions of Euros in cybersecurity and end up suffering an attack because of a human failure. There is little point in following all the best practices if someone then provides data or carries out actions that compromise everything.</p><h3>Don&#8217;t share personal data</h3><p>It is important to start raising your children&#8217;s awareness from an early age not to share personal data - such as their full name, phone number, address, among others - without your assessment and authorization. Since you don&#8217;t know who is on the other side, sharing personal data should only be done when the situation justifies it and the adult understands and accepts the purpose of that collection.</p><p>You should also consider whether the child&#8217;s accounts will be created using their first and last name in the username, or whether they will aim to remain completely anonymous.</p><h3>Be cautious with strangers</h3><p>From a very early age, children are taught not to talk to strangers in the physical world. In the virtual world, they should also be cautious. The truth is that they don&#8217;t know who is on the other side, and the data and profile picture - or even the photographs or videos the other person sends - are not always genuinely of that person.</p><p>Adults can pose as children; boys can pose as girls and vice versa; men can pose as women and vice versa; people with bad intentions can pose as people with good intentions; and so on.</p><p>Over roughly 20 years I have collected several striking stories, some involving people I know personally, which are examples of the dangers that young people can face.</p><p>I&#8217;m sharing two situations with you just as examples, but I could tell you about many more cases.</p><h4>&#8220;The Sausage&#8221;</h4><p>A boy thought he was developing a friendship - or perhaps something more - with a supposed girl he was talking to in an Internet chat. He gained confidence to the point of sharing some rather intimate photographs of himself. The next day, those photographs were all over the school he attended. In other words, the person on the other side was, in fact, a boy or a group of boys posing as a girl.</p><p>They managed not only to win the boy&#8217;s complete trust but also to get him to share something ridiculous. The boy became known as &#8220;The Sausage&#8221; because the situation involved a sausage. He had to leave the school, and the incident is still a topic of conversation today among the former students of that school. Who knows what other impacts it had on the young man and his family.</p><h4>The fight against pedophilia</h4><p>Without wanting to be dramatic - and I know these cases are more extreme, but it is important that we are all aware that they exist - I&#8217;m sharing with Parents and Guardians the work of one of the best (ethical) hackers in the world, <a href="https://ryanmontgomery.me/">Ryan Montgomery</a>, who, together with his friend <a href="https://www.instagram.com/scrappy135mma/">Dustin Lampros</a>, an MMA fighter, has been exposing several cases of pedophiles who, from the Internet, try to arrange meetings with children, most of them around 13 years old.</p><p>The hacker began by reporting several situations that prompted no action from the authorities. So he decided to team up with his fighter friend and, under the name <a href="https://www.youtube.com/@561predcatchers">561 Predator Catchers</a>, to pose as the victims, accepting the meetings proposed by the pedophiles, but with the two of them showing up publicly instead of the child the pedophile expected to find.</p><p>With the evidence, and face to face, they force the pedophiles to admit their intentions, ultimately also making them call their spouses to confess their actions, and then reporting them to the authorities.</p><div id="youtube2-1DpPgZ47RrM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;1DpPgZ47RrM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/1DpPgZ47RrM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3>Share events with Parents and Guardians</h3><p>It is also essential that the dialogue between Parents and their children, or between Guardians and their dependents, be open, and that a safe space be created for children and adolescents to share with their Parents and Guardians what is happening in the virtual world.</p><p>Whether it&#8217;s something they&#8217;re asked, shown, or sent - or, above all, a meeting that someone wants to arrange - this should always be known to the family. But for that, Parents and Guardians must create the conditions for their children and dependents to feel comfortable doing so. We may be moving into an area that belongs more to psychology than to technology, but the key takeaway is that if you want your children and dependents to share these situations with you on an ongoing basis (and not just at a given moment), it is essential that your reaction allows for it, so that they don&#8217;t feel afraid or intimidated. Stay calm, take a deep breath. Make sure you resolve that specific situation, but that you also create the conditions for that channel of sharing to be maintained.</p><h2>Protect Your Home Network</h2><p>This is the point most neglected by people, perhaps because it is technically the most complex, but the goal is simple to understand: it is perhaps on your home network that most of the Internet traffic received and sent by the devices your children use passes through. As much as the devices themselves may be protected, if the network is not, you have a huge security hole.</p><p>In addition to the tips below, you can consult <a href="https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF">here</a> the recommendations of the United States National Security Agency (NSA) on this matter.</p><p>And if you don&#8217;t feel comfortable with this topic, skip to the next one and come back here later.</p><h3>Get a firewall</h3><p>I think few people are aware of this, but the routers that telecom operators install in our homes are not exactly secure. And complaining to your telecom operator probably won&#8217;t get you very far. Those are the models they have available, and they won&#8217;t pay much attention to your cause.</p><p>What you should do, however, is make sure that device is updated from time to time. For example, when you renew your contract, you should demand the replacement of the device. In other words, we&#8217;re not just talking about updating the firmware, but the equipment itself. Given the relatively short cycles of technological updates we experience, the equipment will probably be obsolete by the time the contract is renewed.</p><p>This update is important for the performance of your network, but mainly for security reasons.</p><p>So, these devices are designed to provide you with Internet, cable television, and landline phone services, but they are not exactly designed to keep your network secure. With this in mind, I would not be exaggerating if I said that most homes worldwide end up being, to a certain extent, unprotected.</p><p>Unlike other measures that don&#8217;t require investment, this one requires purchasing equipment (or repurposing an old computer with two network cards). But it is an investment that turns out to be very worthwhile, in that it protects your entire home network (we&#8217;re talking about computers, tablets, smartphones, smart TVs, IoT, etc.) and will allow you something I consider essential, which is to have some visibility over your network.</p><p>In other words, it&#8217;s one thing to use our devices in our home without much awareness of what is going on across the network, and quite another to have a console with a dashboard showing all the information needed to understand whether the traffic is normal or whether there is something strange.</p><p>You will be able to tell whether the protocols being used are normal or not, to and from which countries the traffic is coming, and which services are being used, such as Google, Facebook, Instagram, Microsoft 365, etc. So if something suspicious appears, you can take immediate action.</p><p>You can, for example, block traffic to and from certain countries; that is, if you don&#8217;t want your network to communicate with systems in Russia or China, you can create that block (even though the block can easily be circumvented with a VPN), both for the traffic leaving your home and for the traffic coming in.</p><p>I&#8217;m talking about solutions such as <a href="https://pfsense.org/">pfSense</a>, for more experienced users, or the <a href="https://ui.com/eu/en/cloud-gateways/wifi-integrated/dream-router">Dream Machine</a> from <a href="https://www.ui.com/">UniFi</a>, for less experienced users who value a modern and simple interface, with the added benefit of integrated Wi-Fi.</p><h3>Create separate networks</h3><p>If you work from home, have you ever considered that when you connect your company devices to your home network, you are allowing your personal devices and your company devices to see each other, with all the risks that this can bring to you and to your company or the company you work for?</p><p>And that the devices your children use (who usually click on any link and open any attachment) are also on the same network segment as your devices, which you use to access your bank account, your email, and other personal documents and services of great importance to you?</p><p>Firewalls allow you to create separate networks for specific purposes. That is, you can create a network for your personal devices, another for the devices used by your children, another for IoT devices (assistants, video surveillance cameras, kitchen and vacuum robots, etc.), one just for guests, and, if you work from home, another for company devices.</p><p>Then you can even specify which networks pass through the router&#8217;s physical ports, if you want to connect devices via Ethernet cable, commonly known as a network cable.</p><p>The advantage of this configuration is that if something goes wrong with a device on a particular network, the likelihood of it affecting the devices on the other networks will be much lower, since the networks will be isolated - that is, the devices on one network cannot see the devices on the others.</p><h3>Create separate Wi-Fi networks</h3><p>In addition, you can create Wi-Fi SSIDs for each of these needs and associate them with the VLANs you created.</p><h3>Use WPA3</h3><p>Wi-Fi Protected Access 3 (WPA3) is the most recent standard for Wi-Fi networks, allowing the communication between each device and the Access Point (AP) to use stronger encryption, protection against attacks that under WPA2 made it possible to discover the SSID password, etc.</p><h3>Add your devices to the white list</h3><p>You probably remember from when you were younger that some people managed to figure out their neighbors&#8217; Wi-Fi password and get free Internet that way. Nowadays most homes already have Internet, so this kind of access is no longer done for that purpose, but when it is done it has worse goals, such as spying or attacking.</p><p>With this in mind, adding your devices&#8217; MAC Addresses to the white list and blocking all others gives you additional security.</p><h3>Enable the Intrusion Detection System (IDS)</h3><p>The Intrusion Detection System (IDS) feature makes it possible to detect intrusion attempts and notify the administrator, so that action can be taken. However, it does not make any change to or blocking of the traffic.</p><p>In other words, this means that if an attack is taking place, the IDS will not contain it. It will only inform you of it.</p><h3>Enable the Intrusion Prevention System (IPS)</h3><p>The Intrusion Prevention System (IPS) acts proactively in preventing attacks, seeking to keep them from reaching your internal network.</p><h3>Create traffic rules</h3><p>With traffic rules you can &#8220;be in charge&#8221; of your traffic; that is, you can create inbound and outbound rules that allow or block traffic, based on conditions such as applications or groups of applications (social networks, online games, etc.), domains, IPs, regions, etc., and you can even schedule the times at which the rule applies.</p><h3>Use a VPN</h3><p>A Virtual Private Network (VPN) creates an encrypted tunnel between your device and the VPN server. This means that if someone captures the traffic, they will not be able to interpret it, because it will be encrypted. This gives you privacy, because neither your Internet Service Provider (ISP) nor other entities will be able to see your traffic.</p><p>When choosing a VPN, you should make sure it has a certified no-logs policy - that is, that no data about your traffic is stored - because otherwise you would be protecting yourself from some entities but giving information to the VPN provider.</p><p>VPN services like (affiliate links) <a href="https://go.getproton.me/aff_c?offer_id=26&amp;aff_id=6003&amp;url_id=282">Proton VPN</a>, <a href="https://go.nordvpn.net/aff_c?offer_id=658&amp;aff_id=92382">NordVPN</a>, <a href="http://bitdefender.f9tmep.net/DKOMj2">Bitdefender VPN</a> are recognized as trustworthy.</p><p>VPNs are commonly installed on devices such as computers and smartphones, but installing them at the router level allows all the devices in your home to use the tunnel and therefore be better protected.</p><h3>Receive notifications and monitor traffic</h3><p>Enable notifications to your email or smartphone, and monitor your network from time to time, to ensure that everything is normal.</p><h2>Protect Your Devices</h2><p>Now that your home network is minimally protected, it&#8217;s time to protect your devices.</p><h3>Don&#8217;t routinely use privileged accounts</h3><p>On computer operating systems such as Windows, macOS, or Linux, it is possible to have administrator users and standard (non-administrator) users.</p><p>In your day-to-day use, you should use non-privileged - that is, non-administrator - accounts. The same goes for your children.</p><p>The reason for this is that privileged (administrator) users can perform any kind of task on the computer, such as installing software, changing advanced settings (including security settings), among others.</p><p>By using administrator accounts in your daily routine, you run a greater risk, because in the event of infection, since the user has administration privileges, the malware will be able to more easily install other malicious software or make changes to the computer that it could not make with a standard user.</p><p>In the case of children and adolescents, they will be able to do the same - sometimes installing software without your supervision, which can prove dangerous. They may also make changes or run programs that you don&#8217;t want to be run.</p><p>With this in mind, the whole family should have their own standard account, and only one or a few family members should have administrator accounts. This way, whenever a family member wants to install an application or change more advanced settings, they will have to request permission from the person who knows the administrator password.</p><p>But be careful: you should not share that user&#8217;s credentials with your children, because if you do, they will be able to authorize these tasks themselves without needing your consent.</p><h3>Install antivirus on all devices</h3><p>Another recommendation is to have antivirus on all the devices in your home - that is, not only on yours but also on those of the children/adolescents. This is because if adults fall for tricks (we&#8217;ve all heard news of people who were hacked because they clicked on a link or opened a malicious attachment), minors fall for them even faster, clicking and opening anything.</p><p>An antivirus recognizes malicious files based on their signature, and the more advanced ones include heuristics - that is, they have the ability to identify suspicious behavior. Some test files in a sandbox (i.e., in an isolated environment), thereby being able to tell whether they are malicious or not, even without knowing them beforehand.</p><p>For this reason, antivirus software is a great help in preventing the infection not only of that device but the spread to other devices on the same network.</p><p>An infection that starts on a child&#8217;s device can spread to the devices of Parents or Guardians with severe impacts.</p><p>There are free antivirus programs, but my recommendation goes to the paid ones, in that their identification rate and recovery capability are usually higher, and they also include priority support.</p><p>And it is not always apparent at moment zero that devices are infected. To give you an idea, there are companies that, when they realize they have been attacked, find that the attackers had already had access to their systems for months.</p><p>So invest in good antivirus to protect yourself. You pay for a one-year subscription, and that subscription usually includes more devices, allowing you to protect 5 or 10 devices - which can be computers, tablets, and phones - thus protecting the whole family. You can, for example, use (affiliate link) <a href="http://bitdefender.f9tmep.net/DKOMj2/">Bitdefender</a>.</p><h3>Use a Virtual Private Network (VPN)</h3><p>As mentioned above, a VPN creates an encrypted tunnel between your device and the VPN server, which means that if someone captures the traffic, they will not be able to interpret it, because it will be encrypted. This gives you privacy, because neither your Internet Service Provider (ISP) nor other entities will be able to see your traffic.</p><p>When choosing a VPN, you should make sure it has a certified no-logs policy - that is, that no data about your traffic is stored - because otherwise you would be protecting yourself from some entities but giving information to the VPN provider.</p><p>VPN services like (affiliate links) <a href="https://go.getproton.me/aff_c?offer_id=26&amp;aff_id=6003&amp;url_id=282">Proton VPN</a> <a href="https://go.nordvpn.net/aff_c?offer_id=658&amp;aff_id=92382">NordVPN</a> <a href="http://bitdefender.f9tmep.net/DKOMj2">Bitdefender VPN</a> are recognised as trustworthy.</p><h3>Only use official sources</h3><p>If apps with malware are installed even via the official stores, imagine what happens through unofficial channels. The tip here is to use, as much as possible, only official sources, that is:</p><ul><li><p>On Windows, the <a href="https://apps.microsoft.com/">Microsoft Store</a>;</p></li><li><p>On macOS, the <a href="https://www.apple.com/app-store/">App Store</a>;</p></li><li><p>On Linux, the distro&#8217;s official store;</p></li><li><p>On Android, the <a href="https://play.google.com/">Play Store</a>;</p></li><li><p>On iOS, the <a href="https://www.apple.com/app-store/">App Store</a>.</p></li></ul><p>This doesn&#8217;t mean you can&#8217;t install applications from other sources, which is actually quite common on computers. But in that case you should be extra careful and make sure you are downloading from the official sources.</p><h3>Keep operating systems and applications updated</h3><p>Operating system and application updates don&#8217;t just deliver new features; they also fix bugs and vulnerabilities. It is therefore recommended that you always keep your operating system and applications as up to date as possible.</p><p>I recognize that it&#8217;s a nuisance to have your device unavailable while the update is being installed; however, I emphasize their importance, especially the critical ones, which protect the device from newly discovered threats, thereby preventing them from being exploited against you.</p><h3>Replace devices that have reached End of Life (EOL) and, in particular, End of Support (EOS)</h3><p>Just as it is important that, when renewing your contract with your telecom operator, you request the replacement of your router with a newer one, it is also important to do the same with your devices. Pay attention to the dates on which they reach End of Life (EOL) and especially End of Support (EOS).</p><p>The term End of Life means that the manufacturer has stopped making more of those devices, and End of Support means that it has stopped providing support for them. This means it has stopped releasing updates, such as security updates, which prevent vulnerabilities from being exploited.</p><p>When this happens, the time has come to update your hardware with a new one.</p><p>Naturally, technology is not cheap and it is not always possible for us to stay up to date, but it is important to be aware that the older your devices get, the more vulnerable they are. That is, over time more and more flaws are discovered, and if the device is no longer receiving security updates, the vulnerabilities will become increasingly well known. There are websites on the Internet that list vulnerabilities for the general public.</p><h3>Pay attention to app permissions</h3><p>It is also essential to be careful about the permissions you grant. For example, it may be strange to have a fitness app requesting permission to access your device&#8217;s contacts, or a football scores app requesting permission to access your calls.</p><p>The same can happen with the apps your children install. A game that requests permission to use the camera and the microphone - does it really need that permission?</p><p>When we grant these permissions, we allow these applications to have access to our data or to perform tasks we don&#8217;t want them to perform.</p><p>So pay attention to the permissions you grant, and from time to time carry out a review to remove the permissions that don&#8217;t make sense for the scope of use of the application in question.</p><h3>Uninstall apps you don&#8217;t use; disable features that aren&#8217;t useful to you</h3><p>Kids tend to install endless games. They install one, play it for a while, get bored, search for and install another, play it, get bored, and the cycle repeats for days, weeks, months&#8230; Sometimes Parents or Guardians only notice this when the device gets slow and runs out of space.</p><p>This not only affects the device&#8217;s performance but also increases the likelihood of mishaps. Remember that each app or game you install increases the likelihood of your device having vulnerabilities that can be exploited. So uninstall the apps or games you don&#8217;t use.</p><p>You should have the same mindset with other technologies or features of your device. For example, did you know that Bluetooth has vulnerabilities that are frequently exploited? If you&#8217;re not using it, turn it off. You&#8217;ll save battery and reduce the attack surface.</p><h3>Take special care with cameras and microphones</h3><p>There is nothing more secure than combining software controls with physical controls. That is, if one fails, the other is there to compensate. To give a concrete example, if a particular malicious application activates the camera behind your back, if you have a physical blocker, all the person will see is darkness.</p><p>The same happens if you have a physical microphone blocker. Even if someone bypasses the software controls, they won&#8217;t be able to hear anything - I wrote about this <a href="https://newsletter.nelsonlopes.net/p/stop-your-devices-from-listening-why-microphone-blockers-matter">here</a>.</p><p>Believe me, this happens more often than you think, and more easily than you imagine. And if you don&#8217;t have good antivirus, you could be being spied on without even realizing it - including by apps that hide themselves in the apps menu.</p><p>In the specific case of assistants, disable the microphone whenever they are not being used.</p><h2>Protect Your Online Accounts</h2><p>The cloud has greatly simplified our lives. Consider, for example, swapping devices. We set up a new device with our account and, voil&#224;, our contacts, emails, and photographs are already available on the new device without us needing to transfer them manually.</p><p>The value of the information that online accounts contain is usually quite high for individuals and companies. It is imperative to protect them as best as possible. However, this is not always done, and the consequence is that they can end up being broken into by strangers, unauthorized people.</p><p>And no one wants to have a stranger with access to their emails, reading private documents or notes, viewing family photographs, etc. But to avoid this, it is important that you observe some best practices that I describe below.</p><p>If you want to learn more about this subject, I invite you to read the article I wrote on this topic: <a href="https://newsletter.nelsonlopes.net/p/password-management-best-practices-to-know">Password Management - Best Practices to Know</a>.</p><h3>Set up strong passwords</h3><p>Start by setting up strong passwords. Be aware that short passwords are easily guessed by software widely available on the Internet, and that a password starts to be considered strong from 14 characters onward.</p><p>For a password to be strong, it doesn&#8217;t need to be hard to memorize. A very effective technique is to combine 3 random words, such as &#8220;window-sun-beach&#8221;, apply upper and lower case, add numbers and special characters, and you end up with a password that takes centuries to guess.</p><p>Replacing &#8220;a&#8221; with &#8220;@&#8221;, &#8220;E&#8221; with &#8220;3&#8221;, &#8220;T&#8221; with &#8220;7&#8221;, or &#8220;O&#8221; with &#8220;0&#8221; only makes them harder to memorize and type, and doesn&#8217;t really add security to passwords, because software has long been programmed to do that too. Just to give you an idea, the password &#8220;P@ssw0rd123!&#8221; takes only 2 minutes to crack.</p><h3>Use unique passwords for each service</h3><p>Never use the same password for all your accounts! Strictly speaking, the ideal is for each account to have a unique password that is not used on any other account.</p><p>The mindset here is that if one account is compromised and you use the same password on other accounts, you can already see what is going to happen, can&#8217;t you? Instead of one compromised account, you&#8217;ll have several.</p><p>A concrete example is using the same password for your Gmail and Instagram accounts. If someone discovers your Gmail password, they will not only be able to read your emails but also access your Instagram conversations and, who knows, post in your name.</p><p>Teach this to your children from a young age. Remember that as they grow they will have more and more exposure to technology and, consequently, more and more accounts. Each new account should have a new password.</p><h3>Encourage your child not to share passwords outside the family circle</h3><p>In their innocence, children - and even adolescents - can sometimes share their passwords with friends or schoolmates, and also with other people outside the family circle.</p><p>This is dangerous, because no matter how well intentioned the other person may seem, the temptation to access our private data can be great. Moreover, often the best way to spread a piece of information is to ask someone to keep it secret. That is, what certainty do we have that that person won&#8217;t share our credentials with other people, even more distant from us?</p><p>Don&#8217;t let your young children know account passwords, especially if they contain sensitive data. But if they already have their own accounts or if they know your passwords, do some awareness-raising work to prevent them from being caught out like the people in the video below.</p><div id="youtube2-opRMrEfAIiI" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;opRMrEfAIiI&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/opRMrEfAIiI?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3>Use password managers</h3><p>To help us easily manage the growing number of accounts we have, as well as to simplify the best practices of having passwords that are complex enough not to be easily guessed, different for each service, among others, the use of a password manager is indispensable.</p><p>Services like (affiliate links) <a href="https://go.getproton.me/SH1Aq">Proton Pass</a>, <a href="https://1password.grsm.io/naihf9l2c9l1">1Password</a> and <a href="https://go.nordpass.io/aff_c?offer_id=488&amp;aff_id=92382">NordPass</a> are recognized as trustworthy services and are widely used.</p><h4>Secure storage of passwords</h4><p>First of all, password managers store your credentials securely. This means they use strong cryptography so that, even if their servers are compromised, no one can view your passwords.</p><h4>Organization</h4><p>Password managers also have the great advantage of allowing you to store the whole family&#8217;s credentials in an organized way. That is, you can create virtual vaults in which you store each of the passwords. For example, a vault for your own credentials, another for your child&#8217;s credentials, another for your parents&#8217; credentials (in case you help them in this virtual world), etc.</p><p>In addition, besides the name/label you can give to each of your credentials, you can specify the website address. This way, the password manager will be able to identify the credentials it has to use whenever you access a site where you have an account, simplifying the process.</p><h4>Creation of secure passwords</h4><p>These services usually offer features to generate passwords with the characteristics you want; that is, you can specify the number of characters, whether to include numbers and special characters, and they even indicate the strength of the password you are generating.</p><h4>You only have to memorize a single password</h4><p>That&#8217;s right, you only have to memorize the master password, which you will use to access and decrypt all the others. You don&#8217;t need to memorize any other password, because they will all be stored within the service, so from the moment you are logged in, you can view or copy the passwords you want, or even use browser extensions that do it for you.</p><p>And since you only have to memorize one password, what&#8217;s the issue with generating passwords with 16, 32, or 64 characters for the services you use? The effort of logging in will be the same regardless of the number of characters the passwords have, and at least it ensures they are secure.</p><h4>Simplicity in login: extensions and mobile apps</h4><p>Password managers offer extensions for the best-known and most widely used browsers, as well as apps for Android and iOS, which greatly simplify the entire login process.</p><h3>Enable Multi-Factor Authentication (MFA)</h3><p>Multi-Factor Authentication adds an extra layer of security to your accounts and your children&#8217;s accounts, by requiring one or more authentication factors in addition to the username and password. In other words, without MFA enabled, you can log into the account using just the username and password. If someone somehow discovers that data, they can access your accounts with no further obstacle. With MFA enabled, after entering the correct username and password, it is necessary, for example, to enter another code or approve the login on a different device, which proves that the account is really yours.</p><p>That other code can be sent by SMS, email, or it can be a hardware token or even one from an Authenticator-style app, such as <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;hl=pt">Google Authenticator</a> or <a href="https://www.microsoft.com/pt-br/security/mobile-authenticator-app">Microsoft Authenticator</a>.</p><p>I know it&#8217;s a nuisance to have to resort to extra codes to log into accounts, but believe me, this is a powerful configuration for protecting your accounts. Furthermore, you can increase login simplicity while increasing account security by setting up passkeys or using security keys such as the Yubikey, which allow you to log in without a password.</p><p>Learn more about this subject in the following article I wrote: <a href="https://newsletter.nelsonlopes.net/p/why-you-need-to-activate-multi-factor">Why you need to activate Multi-Factor Authentication (MFA) immediately</a></p><h3>Set up Parental Controls</h3><p>Parental controls allow you, as the name suggests, to have some control over the devices and applications used by your children. When enabled, the device or the application understands that it will be used by a minor, and immediately performs content moderation so that the child only views information appropriate for their age.</p><p>In addition to this adaptation of content to age, it will also allow you to set the total time limit you allow the child to use the device or application. After that time, it gets blocked and the child will have to enter a code to unlock it - a code known only to the parent. That is, you can set your dependent to use the tablet for a maximum of one hour, with the device getting blocked after that hour.</p><p>This way, you complement your household rules with an effective lock, preventing the little ones from taking advantage of a moment when you lose track of time, or while you&#8217;re dealing with other tasks. It also prevents possible secret use.</p><p>These tools also provide access to usage statistics and even notifications, as they are linked to your own device and/or application.</p><p>I do not, in any way, advocate that children should not use technology. On the contrary. I think the teaching of technology lags far behind what are the actual current and future needs, and behind all the doors it opens. People with technological literacy will increasingly have opportunities that cannot be granted to those who lack it. I am also not the right person to talk about the limits that should be set, since that may be a role for psychology professionals. However, I cannot fail to stress the importance of children playing and learning without technology, especially outdoors and with other children, which is why I advocate that limits be set.</p><h3>Protect your bank account</h3><p>One of the problems that occurs fairly often is children buying games, in-game items (such as virtual houses, cars, clothing, or others), or activating subscriptions through the mobile device stores, such as the <a href="https://play.google.com/">Play Store</a> or the <a href="https://www.apple.com/app-store/">App Store</a>. This happens because parents associate their physical debit or credit card details, which is something you should never do.</p><p>Instead, a safer way to avoid unpleasant surprises on your bank statement - from payments made without your consent - is to create bank cards and define what use you want them to have; that is, you can create cards for:</p><ul><li><p>A <strong>single purchase</strong>, where you make a single payment and can&#8217;t buy anything else with that card. In other words, services also can&#8217;t charge you anything more on that virtual card;</p></li><li><p><strong>Multiple purchases</strong>, where you can make several purchases with that card;</p></li><li><p><strong>Recurring payment</strong>, which is useful, for example, for the monthly subscription of a service.</p></li></ul><p>For each of the options above, you can set the card&#8217;s validity, as well as the limit amount that can be charged. You can also cancel the cards at any time, with no impact on your physical card.</p><p>Financial apps are increasingly offering these features, just like the well known <a href="https://www.mbway.pt/">MBWay</a> in Portugal and <a href="https://www.bcb.gov.br/estabilidadefinanceira/pix">Pix</a> in Brazil.</p><p>In addition, and because protection is built in layers, you should configure the app stores to always ask you for the account password before any purchase is authorized. If that password is not shared with your children, they will always have to come to you, regardless of which card is configured. But watch out for shoulder surfing while you enter the password - that is, you should not let your children see the keyboard or the screen while you enter the password. Believe me, they memorize it in an instant!</p><p>Learn more details about this subject in the article I wrote on how to protect bank cards - <a href="https://newsletter.nelsonlopes.net/p/bank-cards-learn-how-to-protect-them">Bank Cards - Learn How to Protect Them</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Bank Cards - Learn How to Protect Them]]></title><description><![CDATA[From Magnetic Stripes to Digital Wallets: The Evolution of Bank Cards and How to Actually Protect Them]]></description><link>https://newsletter.nelsonlopes.net/p/bank-cards-learn-how-to-protect-them</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/bank-cards-learn-how-to-protect-them</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 02 Jun 2026 08:01:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yvPM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Talking about bank cards, such as debit and credit cards, is talking about something very attractive in the world of crime.</p><p>These are some of the attacks carried out on bank cards that it is important to know about, and we will address them in this article, providing the necessary details to help you protect yourself against them:</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ul><li><p>The theft of bank card data, which allows a malicious actor to make payments with them, can be carried out by observing physical cards or compromising platforms where you have used them and that store your data to make it easier for you to use the same cards for future payments;</p></li><li><p>Contactless technologies allow a criminal to bring a payment terminal close to your pocket to make unauthorized payments, as payments up to certain amounts do not require PIN entry, or to copy the data from your bank cards;</p></li><li><p>The cloning of bank cards in ATMs and gas station pumps, using disguised technology;</p></li><li><p>Among others.</p></li></ul><p>Knowing the existing vulnerabilities is essential to protect your payment card accounts from unauthorized transactions.</p><h2>The evolution of payments with bank cards</h2><p>The first bank cards appeared in the 1950s. In the United States, <a href="https://www.dinersclub.com/">Diners Club</a> launched the first multipurpose credit card, made of paper, allowing consumers to make purchases at a limited network of establishments.</p><p>A few years later, in 1958, <a href="https://www.americanexpress.com/">American Express</a> and BankAmericard (now <a href="https://www.visa.com/">Visa</a>) launched their own bank cards.</p><p>In 1966, Master Charge (now <a href="https://www.mastercard.com/">Mastercard</a>) was introduced.</p><p>Get to know the main types of bank cards used today, as well as the most modern ways to make payments.</p><h3>Magnetic stripe bank cards</h3><p>Magnetic stripe cards, <a href="https://www.ibm.com/history/magnetic-stripe">developed by IBM in 1969</a>, store information in a static manner that is read at payment terminals. Since they do not use encryption and the information never changes, they can be easily read and copied onto a blank card by anyone with a magnetic stripe reader, potentially being used for unauthorized payments by the consumer.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yvPM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yvPM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif 424w, https://substackcdn.com/image/fetch/$s_!yvPM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif 848w, https://substackcdn.com/image/fetch/$s_!yvPM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif 1272w, https://substackcdn.com/image/fetch/$s_!yvPM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yvPM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif" width="1024" height="682" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:682,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Cart&#227;o banc&#225;rio de banda magn&#233;tica&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Cart&#227;o banc&#225;rio de banda magn&#233;tica" title="Cart&#227;o banc&#225;rio de banda magn&#233;tica" srcset="https://substackcdn.com/image/fetch/$s_!yvPM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif 424w, https://substackcdn.com/image/fetch/$s_!yvPM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif 848w, https://substackcdn.com/image/fetch/$s_!yvPM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif 1272w, https://substackcdn.com/image/fetch/$s_!yvPM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7efe4b2b-bbd1-4880-b95e-b307a9704888_1024x682.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Magnetic stripe bank card. Credit: <a href="https://pixabay.com/users/ahmadardity-3112014/">AhmadArdity via Pixabay</a></figcaption></figure></div><h3>EMV contact chip bank cards</h3><p><a href="https://www.emvco.com/">EMV</a> contact chip bank cards were first developed in 1994. The first EMV chip cards were launched in Europe in 1996, and global adoption began in 2000. They require physical insertion into payment terminals to complete a transaction and use encryption to generate a unique code for each transaction, known as a cryptogram, which is validated by the bank. Since this code can only be used once, it makes cloning more difficult, thus offering greater security compared to magnetic stripe cards.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T09S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T09S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif 424w, https://substackcdn.com/image/fetch/$s_!T09S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif 848w, https://substackcdn.com/image/fetch/$s_!T09S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif 1272w, https://substackcdn.com/image/fetch/$s_!T09S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T09S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif" width="1024" height="723" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:723,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Cart&#227;o banc&#225;rio de contacto&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Cart&#227;o banc&#225;rio de contacto" title="Cart&#227;o banc&#225;rio de contacto" srcset="https://substackcdn.com/image/fetch/$s_!T09S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif 424w, https://substackcdn.com/image/fetch/$s_!T09S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif 848w, https://substackcdn.com/image/fetch/$s_!T09S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif 1272w, https://substackcdn.com/image/fetch/$s_!T09S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae9fb753-271c-47ad-bf5b-3958fac30289_1024x723.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Contact bank card. Credit: <a href="https://pixabay.com/users/falco-81448/">Falco via Pixabay</a></figcaption></figure></div><p>However, although considered more secure than magnetic stripe cards, they are not completely immune and several attacks are known. Given this, it is important not to let your guard down.</p><h3>EMV chip contactless payment cards</h3><p>EMV contactless cards use <a href="https://en.wikipedia.org/wiki/Near-field_communication">Near-Field Communication (NFC)</a> technology, making them more convenient to use and, in a way, more secure since they do not need to be inserted into payment terminals.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eJT3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eJT3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif 424w, https://substackcdn.com/image/fetch/$s_!eJT3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif 848w, https://substackcdn.com/image/fetch/$s_!eJT3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif 1272w, https://substackcdn.com/image/fetch/$s_!eJT3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eJT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Pagamento contactless&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Pagamento contactless" title="Pagamento contactless" srcset="https://substackcdn.com/image/fetch/$s_!eJT3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif 424w, https://substackcdn.com/image/fetch/$s_!eJT3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif 848w, https://substackcdn.com/image/fetch/$s_!eJT3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif 1272w, https://substackcdn.com/image/fetch/$s_!eJT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F042bad0b-0fbf-486d-8d8f-07eefa21171d_1024x683.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Contactless payment. Credit: <a href="https://www.pexels.com/@towfiqu-barbhuiya-3440682/">Towfiqu Barbhuiya via Pexels</a></figcaption></figure></div><p>However, to maximize their security, it is necessary to store them properly in wallets or cardholders with Radio Frequency Identification (RFID) blocking technology. Otherwise, they are susceptible to data being read without your knowledge. We will discuss this type of wallet further down in this article.</p><h3>Mobile Devices</h3><h4>Contactless Payments (NFC)</h4><p>Mobile payment using devices like smartphones, tablets, and smartwatches through proximity using NFC technology has made payments even more convenient, as we typically have our phone more readily available than our bank cards.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6ecL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6ecL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif 424w, https://substackcdn.com/image/fetch/$s_!6ecL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif 848w, https://substackcdn.com/image/fetch/$s_!6ecL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif 1272w, https://substackcdn.com/image/fetch/$s_!6ecL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6ecL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Pagamento por aproxima&#231;&#227;o com telem&#243;vel&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Pagamento por aproxima&#231;&#227;o com telem&#243;vel" title="Pagamento por aproxima&#231;&#227;o com telem&#243;vel" srcset="https://substackcdn.com/image/fetch/$s_!6ecL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif 424w, https://substackcdn.com/image/fetch/$s_!6ecL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif 848w, https://substackcdn.com/image/fetch/$s_!6ecL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif 1272w, https://substackcdn.com/image/fetch/$s_!6ecL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F11cda2c3-9163-451f-ad30-6d10e341c5b8_1024x683.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Contactless payment with mobile phone. Credit: <a href="https://www.pexels.com/@cottonbro/">cottonbro studio via Pexels</a></figcaption></figure></div><p>In this type of payment, it should be ensured that biometric authentication is requested for each transaction to guarantee that unauthorized payments are not executed.</p><h4>Digital wallets (e-wallets)</h4><p>Digital wallets, such as <a href="https://www.apple.com/apple-pay/">Apple Pay</a> and <a href="https://pay.google.com/about/">Google Pay</a>, become even more convenient by allowing both in-person (NFC) and online payments through the same app.</p><p>These transactions should also be protected with biometric authentication, ensuring that unauthorized payments are not made.</p><h4>QR Codes</h4><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ft0-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ft0-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif 424w, https://substackcdn.com/image/fetch/$s_!ft0-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif 848w, https://substackcdn.com/image/fetch/$s_!ft0-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif 1272w, https://substackcdn.com/image/fetch/$s_!ft0-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ft0-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Pagamento com telem&#243;vel por leitura de QR Code&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Pagamento com telem&#243;vel por leitura de QR Code" title="Pagamento com telem&#243;vel por leitura de QR Code" srcset="https://substackcdn.com/image/fetch/$s_!ft0-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif 424w, https://substackcdn.com/image/fetch/$s_!ft0-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif 848w, https://substackcdn.com/image/fetch/$s_!ft0-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif 1272w, https://substackcdn.com/image/fetch/$s_!ft0-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94f05583-55f1-4222-a6b1-8918f528cf2d_1024x683.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Mobile payment via QR Code scanning. Credit: <a href="https://www.pexels.com/@imin-technology-276315592/">iMin Technology via Pexels</a></figcaption></figure></div><p>The use of QR Codes for making payments is widely adopted, especially due to its simplicity, as it doesn&#8217;t involve inserting or tapping anything - just scanning a QR Code.</p><h2>Physical protection</h2><h3>Store your bank cards securely</h3><p>For some years now, banks have been issuing contactless cards equipped with RFID technology, allowing you to simply tap the card on the payment terminal instead of inserting it and entering a PIN.</p><p>This has undoubtedly simplified payments, but it has also introduced an inconvenience that many have already experienced: if someone brings a payment terminal close to your card while it&#8217;s in your wallet and in your pocket, for example, money can be withdrawn from your account without you even noticing!</p><p>In other words, the infamous pickpockets have had their lives made somewhat easier. Instead of risking being caught stealing a wallet from a pocket, they simply need the right moment to approach with one of these devices. If the payment is below a certain amount (&#8364;50 in Portugal), no PIN is even required.</p><p>Another vulnerability is the copying of card data through proximity.</p><p>To prevent this, you should purchase an anti-RFID wallet, which blocks electromagnetic fields, thus preventing this trick. There are many available on the market to suit all tastes and budgets.</p><h3>Your bank card should be physically non-transferable</h3><p>The most important thing to remember is that your card contains information such as the number, expiration date, and security code (CVV). These three pieces of information are enough for a malicious person to make online payments with your card.</p><p>Taking this into account, think twice before handing your card to anyone.</p><p>Sometimes, store employees, when it&#8217;s time to use the payment terminals, stretch their hands to ask for the card, aiming to insert it into the terminal themselves. Even though the security code is intentionally placed on a different side than the card number and expiration date, there is no reason for you to hand the card to anyone, instead of inserting it directly into the terminal yourself.</p><p>The same applies when bank employees ask for your card to retrieve your account number in order to perform any banking operation. Although these employees have access to sensitive details of your account as part of their role, there is no justification for them to ask for your card. Refuse to hand it over and provide them with your account number instead. Alternatively, using your identification, the bank can easily retrieve your account number.</p><p>These are some of the problems that can occur when you hand your card to others:</p><ul><li><p><strong>Card cloning</strong> &#8211; the store or bank employee could discreetly clone your card using a device they have.</p></li><li><p><strong>Exposure of card data</strong> &#8211; the employee could observe and even copy the details of your card, which would allow them to make online payments or sell the data.</p></li><li><p><strong>Lack of control over the transaction</strong> &#8211; in stores where you are making payments, by not personally placing the card in the terminal, you lose control over the transaction. For example, you may not be able to control the amount you are being charged.</p></li></ul><h3>Pay attention to where you insert your bank card</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LW1G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LW1G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif 424w, https://substackcdn.com/image/fetch/$s_!LW1G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif 848w, https://substackcdn.com/image/fetch/$s_!LW1G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif 1272w, https://substackcdn.com/image/fetch/$s_!LW1G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LW1G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif" width="1024" height="682" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:682,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;ATM / Multibanco&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="ATM / Multibanco" title="ATM / Multibanco" srcset="https://substackcdn.com/image/fetch/$s_!LW1G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif 424w, https://substackcdn.com/image/fetch/$s_!LW1G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif 848w, https://substackcdn.com/image/fetch/$s_!LW1G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif 1272w, https://substackcdn.com/image/fetch/$s_!LW1G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe480584c-ba92-436d-9870-d05b6ae4012b_1024x682.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">ATM / Multibanco. Credit: <a href="https://pixabay.com/users/peggy_marco-1553824/">Peggy_Marco via Pixabay</a></figcaption></figure></div><p>Automated Teller Machines (ATMs), commonly referred to as cash machines, as well as card readers at fuel station pumps, are frequent targets of disguised technology that captures debit and credit card data without the customers suspecting. Before they realize, hundreds or even thousands of Dollars/Euros may have been stolen from their accounts.</p><p>ATMs, many of which are available on the exterior of banks and other locations, provide a convenient way to withdraw money and perform other banking operations without the need to go to the bank and wait for assistance from an employee.</p><p>Gas stations, especially the more recent ones, are equipped with card readers on the pumps, allowing customers to pay for fuel right there, instead of having to go to the attendant inside the counter at the gas station building.</p><p>Despite all the convenience, these devices often lack the same level of surveillance as those found inside banks, making them easy targets for criminals. Card cloning technologies and fake keypads are very similar to the legitimate ones. Some store data internally, requiring criminals to return to the location to collect it, while others transmit it in real-time via mobile data, wireless networks, or Bluetooth.</p><p>Follow these tips to detect fake equipment and avoid falling into these traps:</p><ul><li><p>Pull the keyboard and card reader to check if they come off easily;</p></li><li><p>Pay attention to the spelling on the equipment. Just as often happens in phishing emails, many criminals are not fluent in your language, and spelling mistakes are often indicative of something unusual;</p></li><li><p>If errors occur after inserting the card and entering the PIN, it may indicate that something unusual is happening, and that a criminal may have already received your data.</p></li></ul><p>In addition to these points that can help you detect these devices, there are other ways to avoid falling into these traps, such as:</p><ul><li><p>Use cash whenever possible.</p></li><li><p>Check your card transactions frequently.</p></li><li><p>Avoid ATMs located outside of banks.</p></li><li><p>Always cover the keypad as best as you can while entering your PIN. Some of these schemes involve installing mini-cameras pointed at the keypad, recording the PIN you enter. Although this won&#8217;t prevent your card data from being copied or a cloned card from being used in payment terminals, it will make it harder for criminals to empty your bank account, as they won&#8217;t have your PIN.</p></li></ul><p>That said, it is crucial that these devices are equipped with anti-tampering technology, which prevents the installation of these disguises.</p><p>These attacks are known as <strong>skimming</strong> when they target magnetic stripe bank cards, and <strong>shimming</strong> when the target bank cards contain EMV chips.</p><h4>Skimming</h4><p>Skimming is an older attack targeted at magnetic stripe cards, involving the reading of their data using a card reader. Since the information is static, never changes, and no encryption is used, it is easy to clone these cards.</p><h4>Shimming</h4><p>Shimming is an attack similar to skimming, but aimed at EMV chip cards. It is less common and less effective because, while skimming allows cloning of a magnetic stripe card, shimming captures some data from the EMV chip but cannot generate the unique cryptogram used for each transaction. This cryptogram cannot be reused, so it is not possible to create a functional copy of an EMV card. However, these captured data could be used in transactions where only static data is needed, such as magnetic stripe transactions, if the merchant&#8217;s system security is low.</p><p>It is also worth noting that shimming devices are harder to detect, as they need to be installed inside the equipment, requiring dismantling to identify them. This makes them more challenging to spot compared to traditional skimming devices, which are often more visible and easier to spot by the consumer.</p><h2>Secure Online Payments</h2><h3>Connect to the Internet securely</h3><p>If you are going to make online purchases and therefore share payment details, make sure to:</p><ul><li><p>Use a personal device instead of a public or someone else&#8217;s device. This is an important step in helping to ensure, to some extent, that you are actually visiting the website you intend to and that the data you enter is not intercepted.</p></li><li><p>Use a secure connection. Avoid public wireless (Wi-Fi) networks, such as those found in caf&#233;s, airports, hotels, etc. If you must use them, it is recommended to use a trusted Virtual Private Network (VPN).</p></li></ul><p>Once these steps are ensured, it is also important to verify that you are connecting to the genuine website. That is, type the address of the service you want to access directly or, if you are searching for it on a search engine, be cautious not to click on fake sites posing as the one you want to visit. Well-known cases exist where users are deceived by a site that closely resembles the one they intend to visit. In such cases, the data entered on the site is sent directly to malicious individuals who created it online with the sole purpose of stealing your card details. To avoid this issue, besides being careful when clicking on search results, it is essential to check the address in your browser&#8217;s address bar to ensure that it is indeed the site you want to visit.</p><h3>Prefer services that comply with PCI-DSS</h3><p>No matter how careful you are, when sharing your card details with e-commerce websites, you&#8217;re taking on risks that you can no longer control. If these websites don&#8217;t follow certain precautions, your card details and personal information (such as your name and address) could be accessed by unauthorized individuals.</p><p>Being compliant with the Payment Card Industry (PCI) means adhering to security standards outlined in the <a href="https://www.pcisecuritystandards.org/">Payment Card Industry Data Security Standard (PCI-DSS)</a>. These standards ensure that companies that process, store, or transmit credit card information take the necessary steps to protect cardholder data, preventing data breaches, fraud, and unauthorized access.</p><p>E-commerce platforms like <a href="https://www.shopify.com/">Shopify</a> and <a href="https://woocommerce.com/">WooCommerce</a> strive to comply with PCI-DSS and provide information on the topic at the following links, respectively:</p><ul><li><p><a href="https://help.shopify.com/en/manual/privacy-and-security/account-security/compliance-reports">Viewing Shopify&#8217;s compliance reports</a></p></li><li><p><a href="https://woocommerce.com/document/pci-dss-compliance-and-woocommerce/">PCI-DSS Compliance and WooCommerce</a></p></li></ul><h3>Use virtual cards</h3><p>A virtual card is similar to your physical card, but with some advantages, including:</p><ul><li><p>You can create multiple cards - That is, most services allow you to create multiple virtual cards based on your needs. This means, for example, that you can have a different card for each service you use or, if you prefer, for each payment you make.</p></li><li><p>You can specify whether the card is for one-time use, for multiple purchases, or for recurring payments for a service.</p></li><li><p>You can specify the card&#8217;s maximum spending limit.</p></li></ul><p>In addition to these advantages, you can cancel any virtual card at any time. That means if you cancel a subscription to a particular service and want to ensure that the cancellation is effective, you can cancel the card. This way, if the service tries to charge the subscription fee, they won&#8217;t be able to. However, before canceling a card, check which services are being charged to it, as canceling the card will affect them all.</p><h2>Conclusion</h2><p>In summary, the important takeaway is that your card data is of great interest to those involved in the criminal world, so:</p><ul><li><p>Avoid magnetic stripe credit cards and prefer EMV chip cards as they are more secure. Use NFC or QR Code payments when possible, preferably configured to require authentication with biometric data.</p></li><li><p>You should never hand your physical card to another person.</p></li><li><p>You should never share your physical card details (such as the number, expiry date, and security code) in person or online. Instead, create virtual cards with usage limits.</p></li><li><p>You should store your cards in RFID-blocking wallets to prevent payment terminals from being placed near your pocket, making unauthorized payments, or attempting to read your card data.</p></li><li><p>You should pay special attention to ATMs and fuel station pumps, as they are common targets for disguised technology aimed at cloning your cards.</p></li><li><p>Make online payments using your own devices and internet connections, and ensure that you use reputable e-commerce services that comply with PCI-DSS.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Password Management - Best Practices to Know]]></title><description><![CDATA[The Practical Habits That Keep Your Accounts Safe in 2026]]></description><link>https://newsletter.nelsonlopes.net/p/password-management-best-practices-to-know</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/password-management-best-practices-to-know</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 26 May 2026 08:01:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!imRA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Passwords, along with usernames, remain the primary data used to access online accounts. Poor management of them is also one of the main causes of account breaches for both individuals and companies. In this article, recommendations for good password management are outlined, aiming to ensure greater protection of your accounts.</p><h2>The Evolution of Passwords</h2><h3>Simple Passwords and Stored Without Security</h3><p>Initially, passwords were short and stored in plain text (without any encryption) in systems. Any intruder who gained access to the database where they were stored could view these passwords, as they were saved in a readable format. Since people typically used the same email and password across multiple systems, these intruders could access several accounts of the same individuals with little effort.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3>Hashing and Encryption</h3><p>Systems began converting passwords into hashes using cryptographic hash functions. In other words, the password was no longer stored, only its hash. Whenever the user logged in, their password was converted into a hash using the same algorithm, and this hash was compared with the one stored in the database. This ensured that even if an attacker obtained the file or database, they could not easily recover the original passwords, as hash functions are irreversible.</p><p>Later, it became clear that although moving from storing passwords to storing their hashes was a significant improvement, it was not enough to store user credentials securely due to an attack known as rainbow tables. In this attack, intruders had tables with hashes and their plaintext equivalents. As a result, today it is recommended to add a salt to the password and convert the password + its salt into a hash. This ensures that even if two users have the same password, the result of password + salt will be a different value, making it much more complex to crack.</p><h3>Increased Complexity</h3><p>As users were creating passwords that were too simple, it became possible to crack them using brute force or dictionary attacks. As a result, companies began implementing policies that required frequent password changes (at least every 90 days), as well as increasing password complexity. This meant requiring passwords to contain uppercase and lowercase letters, numbers, and/or special characters. The prohibition of reusing previous passwords was also introduced.</p><h3>Multi-Factor Authentication (MFA)</h3><p>Due to the rise in phishing attacks and keyloggers, Multi-Factor Authentication (MFA) was introduced. Now, in addition to the username and password, another factor was required, such as a code sent via SMS to the user&#8217;s mobile phone or a hardware token.</p><p>One-Time Password (OTP) systems, such as Google Authenticator (<a href="https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;hl=en">Android</a>; <a href="https://apps.apple.com/us/app/google-authenticator/id388497605">iOS</a>) and Microsoft Authenticator (<a href="https://play.google.com/store/apps/details?id=com.azure.authenticator&amp;hl=en">Android</a>; <a href="https://apps.apple.com/us/app/microsoft-authenticator/id983156458">iOS</a>), were also implemented.</p><p>If you want to get familiar with Multifactor Authentication, read this: <a href="https://newsletter.nelsonlopes.net/p/why-you-need-to-activate-multi-factor">Why you need to activate Multifactor Authentication (MFA)</a></p><h3>Password Managers</h3><p>As the number of accounts per individual grew, password management systems began to emerge. These systems allowed passwords to be stored securely (using advanced encryption) and organized, as well as accessed in a simple manner.</p><p>In addition, they included a password generation feature, allowing users to create long and complex passwords without the need to memorize them. They also encouraged the use of unique passwords for each system.</p><h3>Elimination of Passwords and Biometrics</h3><p>Currently, we are witnessing a transition to passwordless authentication. Protocols like FIDO2, which are considered highly resistant to phishing, enable authentication without the need for passwords, using passkeys and physical security keys, such as <a href="https://www.yubico.com/">Yubikeys</a>, among others.</p><p>This approach makes the authentication process not only more secure but also simpler, by using methods such as biometrics&#8212;e.g., fingerprint scanning or facial recognition.</p><h3>But in the present, the mistakes of the past are still being made.</h3><p>Unfortunately, even today, there are systems where passwords are stored in plaintext or hashed without a salt; individuals and companies that still don&#8217;t enforce a secure minimum password length; a low rate of Multi-Factor Authentication usage (whether it&#8217;s due to systems that still don&#8217;t offer it, or users who, despite systems having it available, haven&#8217;t activated it), and more.</p><h2>How long does it take for a password to be discovered?</h2><p>The following graph shows the strength of some passwords, highlighting that the length, that is, the number of characters, is what gives them the most strength, making them harder to guess with each additional character.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!imRA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!imRA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif 424w, https://substackcdn.com/image/fetch/$s_!imRA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif 848w, https://substackcdn.com/image/fetch/$s_!imRA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif 1272w, https://substackcdn.com/image/fetch/$s_!imRA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!imRA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif" width="952" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:952,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A for&#231;a de algumas passwords&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A for&#231;a de algumas passwords" title="A for&#231;a de algumas passwords" srcset="https://substackcdn.com/image/fetch/$s_!imRA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif 424w, https://substackcdn.com/image/fetch/$s_!imRA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif 848w, https://substackcdn.com/image/fetch/$s_!imRA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif 1272w, https://substackcdn.com/image/fetch/$s_!imRA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d929fb2-9f6f-4787-8d90-7047b869388e_952x1024.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The strength of some passwords. Credit: <a href="https://bitwarden.com/">Bitwarden</a></figcaption></figure></div><p>You can test some passwords and see how long it would take for them to be cracked <a href="https://bitwarden.com/password-strength/">here</a>.</p><h2>What are secure passwords?</h2><p>The answer to this question has changed over time. For example, in 2003, when NIST Special Publication 800-63, Appendix A was published, it recommended that passwords should contain uppercase and lowercase letters, at least one special character, and at least one number. It also advised that passwords should be changed frequently, at least every 90 days.</p><p>This led most users to replace some characters with numbers, which became highly predictable, even for software programs designed to guess passwords. Knowing that these substitutions were common, developers programmed the software to also make those substitutions. This could result in the password &#8220;P@ssW0rd123!&#8221; to be cracked in 6 minutes or less.</p><p>The requirement to change the password every x days also led users to only add or replace one character, keeping the rest of the password unchanged, which does not provide a significant security improvement.</p><p>The cartoonist Randall Munroe published a <a href="https://xkcd.com/936/">comic on xkcd that became popular</a> by highlighting that the password &#8220;Tr0ub4dor&amp;3&#8221; (something like &#8220;Tr0v4d0r&amp;3&#8221;, meaning troubadour with substitutions and additions) could be cracked in just three days, due to the predictable use of uppercase and lowercase letters, character substitutions with numbers, and the use of special characters. Meanwhile, the password &#8220;correct horse battery staple&#8221; would take 550 years to crack. He also commented that &#8220;After 20 years of effort, we&#8217;ve correctly trained everyone to use passwords that are hard for humans to remember, but easy for computers to guess.&#8221;</p><p>You will probably agree that the passphrase &#8220;correct horse battery staple&#8221; is easier to remember than the password &#8220;Tr0v4d0r&amp;3,&#8221; especially if you visualize an image in your mind.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nINU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nINU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif 424w, https://substackcdn.com/image/fetch/$s_!nINU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif 848w, https://substackcdn.com/image/fetch/$s_!nINU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif 1272w, https://substackcdn.com/image/fetch/$s_!nINU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nINU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif" width="740" height="601" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/67915379-c902-451b-b381-bcc625680dec_740x601.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:601,&quot;width&quot;:740,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A for&#231;a das passwords&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A for&#231;a das passwords" title="A for&#231;a das passwords" srcset="https://substackcdn.com/image/fetch/$s_!nINU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif 424w, https://substackcdn.com/image/fetch/$s_!nINU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif 848w, https://substackcdn.com/image/fetch/$s_!nINU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif 1272w, https://substackcdn.com/image/fetch/$s_!nINU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67915379-c902-451b-b381-bcc625680dec_740x601.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The strength of passwords. Credit: <a href="https://xkcd.com/">xkdc</a></figcaption></figure></div><p>The author of the NIST document, Bill Burr, later <a href="https://www.theverge.com/2017/8/7/16107966/password-tips-bill-burr-regrets-advice-nits-cybersecurity">expressed regret</a> for these recommendations, which were misinterpreted and led users to adopt predictable practices, even though his recommendations aimed to make passwords more robust.</p><p>The National Institute of Standards and Technology (NIST) published a new document, known as <a href="https://csrc.nist.gov/pubs/sp/800/63/3/upd2/final">NIST Special Publication 800-63-3</a>, in 2017, which was revised in 2020. This document is widely adopted by the industry as a reference for authentication management and identity security.</p><h3>Use long passwords</h3><p>One of the main factors, if not the most important, that makes a password secure is its number of characters. The more characters it has, the harder it is to guess.</p><p>Short passwords are easily guessable in an attack known as brute force, where software tests all possible character combinations. It&#8217;s a time-consuming process, but it can sometimes yield quick results, especially when the passwords are too short.</p><p>Nowadays, none of your passwords should be less than 14 characters.</p><p>Ideally, you should create passphrases instead of passwords, meaning using a phrase. Joining words like &#8220;I like Nelson Lopes&#8217; newsletter,&#8221; along with numbers and other characters, can create an excellent password.</p><h3>Use random words</h3><p>Avoid using passwords that contain words related to you or someone close to you. These words are the first to be tried, especially based on what the attacker knows about you (for example, what you share on social media).</p><p>In other words, creating passwords with data that could lead back to you is half the battle for them being cracked. For this reason, it&#8217;s good practice for passwords not to include the username of the associated account, your name or the names of close family members, your birthdate, your phone number, etc.</p><p>The goal is to choose a passphrase that contains words that don&#8217;t make sense together, making it harder for any system to guess them.</p><h3>The replacement of characters with their numeric counterparts no longer works</h3><p>At one point, some characters were replaced with similar-looking numbers, such as &#8220;E&#8221; with 3, &#8220;T&#8221; with 7, and so on. But just as account holders made these substitutions, the software used by attackers to crack passwords was also programmed to do the same. Taking this into account, this type of substitution no longer provides strength to passwords.</p><h3>Do not repeat passwords</h3><p>One of the main mistakes people make is using the same password for multiple accounts. Imagine that somehow someone discovers the password for one of your accounts. By knowing your username or email, they can now try the same password across several other services.</p><p>In other words, to give a concrete example, suppose you use the same password for Instagram as for Gmail. If someone happens to discover your Gmail account, they will also be able to access your Instagram account. Not only will they be able to read your emails, but they may also read your Instagram conversations and, who knows, even post on your behalf.</p><p>If you use business systems, it is very important for both you and the company you work for that you don&#8217;t use the same passwords for your personal accounts and your business accounts, and vice versa. This is for similar reasons as described above - if any of your personal accounts are compromised, your business accounts are more likely to be compromised as well, leading to significant negative impacts for the organization. On the other hand, if the company&#8217;s accounts are compromised, the attack may extend to your personal accounts, which I&#8217;m sure you want to avoid!</p><p>All of this can be solved simply: each account should have a password different from all the others.</p><h3>Do not reuse passwords</h3><p>At this point, what I want to tell you is not to use passwords you&#8217;ve used in the past. They surely have some trace on your side or on the systems where you used them. Let your imagination flow and create new passwords.</p><h3>Organizations should not require password changes. This does not mean that you shouldn&#8217;t change your passwords</h3><p>NIST, along with other organizations, does not recommend password changes based on studies that showed this practice often led users to adopt predictable and weak passwords. A password change is only recommended if you suspect it has been compromised.</p><p>Therefore, they encourage organizations not to require frequent password changes, unlike the previous recommendation that sought to enforce a change at least every 90 days, and they complement this recommendation with the advice to have <a href="https://nelsonlopes.me/multifactor-authentication-mfa-what-is-it/">Multi-Factor Authentication</a> enabled.</p><p>The user is no longer required to change the password; however, they should keep in mind that one way to ensure that if a particular account is compromised, unauthorized access by third parties is not continuous (even when unaware of the breach), is to periodically change their passwords. This is especially important for services that still don&#8217;t offer MFA (which, unfortunately, are still many), but also for those that do, as we know that certain MFA methods can be vulnerable.</p><h3>Be mindful of where you store your passwords</h3><p>Never store your passwords in places where they are in plain text, without encryption. For example, you should never store them:</p><ul><li><p>On paper, such as post-its;</p></li><li><p>In computer or phone notes;</p></li><li><p>In spreadsheets;</p></li><li><p>On the covers of mobile devices;</p></li><li><p>Etc.</p></li></ul><p>If you do this, anyone with access to the paper or your session, physically or remotely, will be able to read the password. This is, in fact, one of the most common mistakes. It&#8217;s quite practical because the password stays on a post-it stuck to the monitor or in a file on the desktop, ready to be copied to the login page&#8230; by you and by anyone else who can access it, as it&#8217;s fully readable.</p><p>The ideal way to combat this and still maintain simplicity is to use a password manager, as I discuss further down in this article.</p><h3>Do not store your passwords in browsers</h3><p>Browsers have had the ability to store credentials for some time now, aimed at simplifying the user&#8217;s task. However, their use is not recommended because many don&#8217;t use robust encryption methods, and someone with physical access to the machine can extract them.</p><h3>Do not share your passwords, but if you do, make sure to do it securely</h3><p>If you share the password to your Netflix account with a friend so they can watch movies without paying, and use the same password for Gmail, you can see what might happen, right? And it&#8217;s not just about your friend, who might even be an honest person, but do you have guarantees that they will store that password properly?</p><p>Especially in the business world, it&#8217;s very common for users to share their passwords with colleagues when they go on vacation or are on leave, so colleagues can follow up on received emails and other matters. Don&#8217;t do this! And if you&#8217;re in charge of a department or have the ability to enforce security policies, prohibit people from doing so. Instead, they should request the IT department to forward emails and calls from the absent person to their substitute.</p><p>The truth is that the more people you share your password with, the greater the risk to your account. I don&#8217;t know if you store your passwords properly or not, but remember that the person you&#8217;re sharing your credentials with may not take the same precautions.</p><p>Remember: the responsibility to protect your account is not just that of the service provider or your company&#8217;s IT department (if applicable), it is also yours.</p><p>However, sometimes we do need to share a password. In these cases, email and SMS are channels to avoid! Use password managers like (affiliate links) <a href="https://go.getproton.me/SH1Aq">Proton Pass</a>, <a href="https://1password.grsm.io/naihf9l2c9l1">1Password</a> or <a href="https://go.nordpass.io/aff_c?offer_id=488&amp;aff_id=92382">NordPass</a>, which offer secure password sharing functionality, or use secure communication apps like <a href="https://signal.org/">Signal</a> or <a href="https://telegram.org/">Telegram</a>.</p><h3>Use a Password Manager</h3><p>Password managers allow you to store all your passwords securely (data is encrypted), in a simple and organized way, making the management of your credentials much easier. Believe me, when used properly, they are a true game changer.</p><p>With a password manager, you only need to remember one password - the master password. Yes, just one: the one required to decrypt all the others. This password should be long and complex, but you must ensure it&#8217;s one you can remember because if you forget it, you might lose access to all the others.</p><p>So, what difference does it make to create the remaining passwords with 32 or even 64 characters? I know this might seem daunting or even ridiculous to some people, but&#8230; give it a try. It won&#8217;t make any difference to you since the passwords will be automatically filled by your password manager, or you&#8217;ll just need to copy them. You won&#8217;t have to memorize or type them, and you&#8217;ll have the confidence of using a secure password! Of course, this depends on whether the service allows such long passwords. Unfortunately, many services still limit passwords to only 8 or 10 characters, which is incomprehensible.</p><p>You can organize your passwords into vaults. For example, you can have a vault where you store the credentials for your personal accounts, another for your partner&#8217;s credentials, another for your children, one for work, and so on.</p><p>You can use browser extensions that automatically fill in credentials on the websites you visit. The most well-known password managers offer extensions for the most widely used browsers.</p><p>They have mobile apps that do the same for the applications you install, whether on Android or iOS.</p><p>They can be local or cloud-based. If you don&#8217;t trust the cloud enough to store such sensitive data there, you can use password managers like <a href="https://keepass.info/">Keepass</a>, whose database remains only on the device where it is installed. However, if you want to access the data on another device, you&#8217;ll need to copy the database to that device. This might not be very practical because, whenever you add or change a password, you&#8217;ll have to update it on both devices or copy the database from one to the other again. Some people use online file services to synchronize the database across devices, but this is not as simple as directly using a cloud service like (affiliate links) <a href="https://go.getproton.me/SH1Aq">Proton Pass</a>, <a href="https://1password.grsm.io/naihf9l2c9l1">1Password</a>, <a href="https://go.nordpass.io/aff_c?offer_id=488&amp;aff_id=92382">NordPass</a>, etc.</p><h3>Enable Multi-Factor Authentication (MFA)</h3><p>No matter how secure a password is, you should always keep in mind that it can be discovered. For instance, if your device has a keylogger, every keystroke is recorded and sent to the attacker. In this case, no matter how complex your password is, its complexity becomes irrelevant once it is transmitted to the perpetrator.</p><p>To help resolve this and other issues, Multi-Factor Authentication (MFA) adds an extra layer of security to your accounts by requiring another factor whenever you log in. For example, this factor could be a One-Time Password (OTP) generated on your mobile device, through an Authenticator app, which you must enter on the website you&#8217;re logging into in order to gain access. In this case, in addition to your password, your device would be required to successfully log into the account.</p><p>Know more about Mulfitactor Authentication in this article: <a href="https://newsletter.nelsonlopes.net/p/why-you-need-to-activate-multi-factor">Why you need to activate Multi-Factor Authentication (MFA) immediately </a></p><h3>Go passwordless</h3><p>As we know, passwords are vulnerable and remain a challenge in securing online accounts. However, there are protocols designed to address the weaknesses of passwords, making access more secure and simple. Click <a href="https://newsletter.nelsonlopes.net/p/why-you-need-to-activate-multi-factor">here</a> for more details.</p><h2>Other precautions</h2><p>In addition to the best practices mentioned above, which are more directly related to passwords themselves, there are a number of other concerns you should keep in mind.</p><h3>Use a secure internet connection</h3><p>It is known that even our home connection is not completely private, as the ISP (Internet Service Provider) can see where we are browsing and even view traffic that is not encrypted.</p><p>Worse than this is the use of public Wi-Fi networks, such as in cafes, airports, or hotels.</p><p>Consider using a VPN that encrypts all your traffic from your device to the VPN server you&#8217;re connected to. This way, all systems in between will only see encrypted traffic and won&#8217;t be able to decipher what is passing through. However, you should be cautious when choosing a VPN service. Specifically, the VPN should be audited to ensure that it does not keep logs of your browsing activities, as just like the ISP can see your traffic if you don&#8217;t use a VPN, the VPN provider will also be able to view it.</p><p>Services like (affiliate links) <a href="https://go.getproton.me/aff_c?offer_id=26&amp;aff_id=6003&amp;url_id=282">Proton VPN</a>, <a href="https://go.nordvpn.net/aff_c?offer_id=658&amp;aff_id=92382">NordVPN</a> and <a href="http://bitdefender.f9tmep.net/DKOMj2">Bitdefender VPN</a> are recognized as trustworthy services.</p><h3>Only visit HTTPS sites</h3><p>When you access a site whose address starts with HTTP://, it means that the traffic between your device and the website&#8217;s server is not encrypted. When this happens, if the traffic between your device and the server is intercepted, the data, including your password, is readable by third parties.</p><p>Always check if the address you are accessing starts with HTTPS:// or if there is a closed padlock (sometimes green) next to the address bar, as seen when visiting <a href="https://nelsonlopes.me/">nelsonlopes.net</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!r5QH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!r5QH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif 424w, https://substackcdn.com/image/fetch/$s_!r5QH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif 848w, https://substackcdn.com/image/fetch/$s_!r5QH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif 1272w, https://substackcdn.com/image/fetch/$s_!r5QH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!r5QH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif" width="240" height="34" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/86001e8c-5c82-41b9-a044-871670709131_240x34.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:34,&quot;width&quot;:240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Liga&#231;&#227;o segura ao nelsonlopes.net&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Liga&#231;&#227;o segura ao nelsonlopes.net" title="Liga&#231;&#227;o segura ao nelsonlopes.net" srcset="https://substackcdn.com/image/fetch/$s_!r5QH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif 424w, https://substackcdn.com/image/fetch/$s_!r5QH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif 848w, https://substackcdn.com/image/fetch/$s_!r5QH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif 1272w, https://substackcdn.com/image/fetch/$s_!r5QH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F86001e8c-5c82-41b9-a044-871670709131_240x34.avif 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Secure connection to nelsonlopes.net</figcaption></figure></div><p>HTTP stands for <strong>H</strong>yper <strong>T</strong>ext <strong>T</strong>ransfer <strong>P</strong>rotocol, and HTTPS stands for <strong>H</strong>yper <strong>T</strong>ext <strong>T</strong>ransfer <strong>P</strong>rotocol <strong>S</strong>ecure. The Transport Layer Security (TLS), which replaced Secure Sockets Layer (SSL) and corrected several of its vulnerabilities, is the protocol responsible for encrypting communication in HTTPS.</p><h3>Always check the website address you are visiting</h3><p>Is the website you are accessing the one you intend to visit, or is it an exact copy? Pay close attention to the address in the browser&#8217;s address bar. There are well-known cases where the similarities are so strong that the user enters their credentials on a fake website, thinking they are on the real one. Believe me, there are exact copies where the differences are even hard for the trained eye to spot.</p><p>To avoid being deceived, always check the address.</p><h3>Notifications when you log in</h3><p>Prefer services that send notifications whenever you log in. This way, if you receive one of these notifications and you are not logging in, you will know that something is wrong and should act quickly to minimize the issue.</p><p>If the system does not send these notifications, check if it shows the last login or has a visible login log. If it does, take a look from time to time to make sure everything is fine or to detect any issues. If you suspect that a login wasn&#8217;t yours, reset the password immediately.</p><h3>Account lockout due to wrong attempts and CAPTCHA</h3><p>Also, prioritize services that lock the account (temporarily or permanently) after a certain number of failed login attempts. This way, brute force and dictionary attacks are ineffective, as these processes are already slow (when passwords are secure), and with these locks, they become impractical.</p><p>Websites should also use CAPTCHA systems (Completely Automated Public Turing test to tell Computers and Humans Apart) to filter human users from bots.</p><h3>Secure password storage</h3><p>Prioritize services that do not store your passwords. Yes, that&#8217;s right, I repeat, prioritize services that do not store your passwords. Services should never store the passwords of their users, but rather their hashes.</p><p>But this is not enough, as it would still be vulnerable to rainbow table attacks. A salt should be added to the password before hashing the password + salt.</p><h2>How to test if the password is secure?</h2><p>Password managers themselves usually have the functionality to indicate whether each of your passwords is secure, even alerting you to those that are not. Some even have statistics so you can get a quick overview of the status of your credentials.</p><p>In addition to these, there are some online services that also perform this check, like <a href="https://bitwarden.com/password-strength/">this one</a>.</p><h2>Conclusion</h2><p>Attacks to discover credentials have evolved over time, along with computational power, greatly reducing the wait time for those engaging in such activities. To counter this, it is essential to pay attention to some basic precautions described in this article. These precautions can be applied directly by the reader, but others must be implemented by the services they use. Therefore, it is important to manage your passwords well, but also to stay vigilant about the quality of the services where you store your information.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[X updated its For You page algorithm - Here's what works now]]></title><description><![CDATA[Plus: How I went through the 20,000+ lines of code of X's For You algorithm]]></description><link>https://newsletter.nelsonlopes.net/p/x-updated-its-for-you-page-algorithm</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/x-updated-its-for-you-page-algorithm</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 19 May 2026 08:02:03 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b84254ab-e173-45bf-821c-750ad1ba08b3_2074x1154.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hi there,</p><p>X, formerly Twitter, the social network owned by Elon Musk, just updated its For You page algorithm and I went through the 20000+ lines of code to analyze it and create this article, so you can understand what actually works now when posting to X.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>I mean, maybe I didn&#8217;t actually go through all those 20000+ lines myself&#8230; there&#8217;s a chance I shortened it with AI &#128519;</p><p>The X For You page algorithm is now open-source here: <a href="https://github.com/xai-org/x-algorithm">https://github.com/xai-org/x-algorithm</a>, so I started by cloning the repo to my computer. </p><p>You can do the same with this command:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;195c57b5-025b-4416-90ec-b0b371bbc50f&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">git clone https://github.com/xai-org/x-algorithm.git</code></pre></div><p>Then, move into the downloaded directory with this command:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;beff99e7-d110-4275-a960-f28d38969ae0&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">cd x-algorithm</code></pre></div><p>And execute Claude Code:</p><div class="highlighted_code_block" data-attrs="{&quot;language&quot;:&quot;plaintext&quot;,&quot;nodeId&quot;:&quot;6843ad26-37ce-43ce-b10d-66671234f396&quot;}" data-component-name="HighlightedCodeBlockToDOM"><pre class="shiki"><code class="language-plaintext">claude</code></pre></div><p>You should then see a window similar to this one:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k4UI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k4UI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png 424w, https://substackcdn.com/image/fetch/$s_!k4UI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png 848w, https://substackcdn.com/image/fetch/$s_!k4UI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png 1272w, https://substackcdn.com/image/fetch/$s_!k4UI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k4UI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png" width="1296" height="906" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:906,&quot;width&quot;:1296,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:295743,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.nelsonlopes.net/i/198153029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k4UI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png 424w, https://substackcdn.com/image/fetch/$s_!k4UI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png 848w, https://substackcdn.com/image/fetch/$s_!k4UI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png 1272w, https://substackcdn.com/image/fetch/$s_!k4UI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2c81a4f0-b1b8-4c73-81c9-d38ce04cf5a0_1296x906.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I told Claude what the directory contained and asked it to analyze the entire codebase.</p><h1>What Actually Works in X&#8217;s New For You Algorithm</h1><p>Optimize for the full action surface, not just likes.</p><p>Every time you post, the algorithm gives your content a <strong>score</strong>. Positive engagement (likes, replies, reposts, bookmarks, time spent) increases that score. Negative engagement (hides, blocks, &#8220;not interested&#8221;, quick scrolls) decreases it.</p><p>The algorithm applies <strong>decaying scores</strong> to subsequent posts from the same account per feed request, meaning every extra post you make gets shown to fewer people. <strong>This should significantly reduce spam</strong> on the For You feed.</p><p>The algorithm also has specific logic designed to detect if a post has <strong>banger potential</strong>, and actively penalizes low-quality, generic, or AI-generated content.</p><p>You&#8217;ll now see <strong>more content from people you actually follow</strong> (in-network). Their posts get a higher score, so the algorithm is pushing more of what comes from your network.</p><p>The combination of reduced dwell time and lower click-through to X&#8217;s own content <strong>makes external links a well-established penalty</strong>.</p><p><strong>NSFW, violence, gore, and toxicity will not help your content stand out</strong>. In fact, the algorithm actively penalizes this type of content.</p><p><strong>Quality beats follower count</strong>. Small accounts can now achieve massive reach, as long as they create content that keeps people engaged for a long time.</p><p><strong>Undisclosed ads will get almost zero reach.</strong></p><p><strong>Microniches are the big winners</strong>. If you stay consistent in a specific microniche and deliver high-value content, you can grow extremely fast. Avoid mixing too many different topics. Focus is heavily rewarded now.</p><p><strong>Start making videos</strong>. X is now clearly becoming a <strong>video-first platform</strong>. Add captions/subtitles, because a huge portion of people watch videos on X with the sound off. Good captions will dramatically increase the time people spend watching and boost your reach.</p><p><strong>Engagement velocity in the first 30-60 minutes</strong> is critical.</p><p>Below is Claude Code&#8217;s output.</p><h2>Claude Code&#8217;s output</h2><h3>General Architecture &#8212; 8-step pipeline (Home Mixer)</h3><p>Query Hydration &#8594; Candidate Sources &#8594; Candidate Hydration &#8594; Filtering</p><p>  &#8594; Scoring &#8594; Selection &#8594; Post-Selection Filtering &#8594; Feed Response</p><p></p><h3>Scoring System &#8212; Phoenix model</h3><p>Grok-based transformer that predicts the probability of 19 simultaneous actions. Final score = weighted sum:</p><p>Score = &#931; (weight_i &#215; P(action_i))</p><h4>Positive actions (by weight order):</h4><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/wq1Xo/1/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e59adb67-c77e-4f9d-9ee6-3ab597843863_1220x1058.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/073b1ee9-b7f1-4fb5-9866-bd33d91e452f_1220x1058.png&quot;,&quot;height&quot;:519,&quot;title&quot;:&quot;Created with Datawrapper&quot;,&quot;description&quot;:&quot;&quot;}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/wq1Xo/1/" width="730" height="519" frameborder="0" scrolling="no"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><h4>Negative actions:</h4><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/n6Nu0/2/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77305d4c-91f4-4139-ae43-a5d0739a802a_1220x614.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e76e4453-528a-497a-ab3b-ecd9cabba6a5_1220x546.png&quot;,&quot;height&quot;:297,&quot;title&quot;:&quot;Created with Datawrapper&quot;,&quot;description&quot;:&quot;&quot;}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/n6Nu0/2/" width="730" height="297" frameborder="0" scrolling="no"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><p></p><h3>Candidate Sources</h3><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/2gmPY/2/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9eed4769-a807-4187-8899-cdc72932c578_1220x530.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2eadc451-b456-4684-89bc-0aa457a25476_1220x530.png&quot;,&quot;height&quot;:244,&quot;title&quot;:&quot;Created with Datawrapper&quot;,&quot;description&quot;:&quot;&quot;}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/2gmPY/2/" width="730" height="244" frameborder="0" scrolling="no"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><p></p><h3>Hydrators &#8212; factors that boost score</h3><ol><li><p><strong>has_media = true</strong> &#8212; image or video present</p></li><li><p><strong>VQV_WEIGHT</strong> &#8212; video longer than MIN_VIDEO_DURATION_MS and actually watched</p></li><li><p><strong>engagement_counts</strong> &#8212; fav_count, reply_count, repost_count, quote_count</p></li><li><p><strong>author_followers_count</strong> &#8212; accounts with more followers get more visibility</p></li><li><p><strong>mutual_follow_jaccard</strong> &#8212; author followed by people you follow</p></li><li><p><strong>language_code</strong> &#8212; feature passed to the model (no explicit filter)</p></li></ol><p></p><h3>Filters (pre and post scoring)</h3><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/Jp0bA/1/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/da22ece2-9bf7-4a8f-a6d8-d52080a3e986_1220x762.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eda61295-b317-4f69-9788-375463c163c0_1220x762.png&quot;,&quot;height&quot;:371,&quot;title&quot;:&quot;Created with Datawrapper&quot;,&quot;description&quot;:&quot;&quot;}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/Jp0bA/1/" width="730" height="371" frameborder="0" scrolling="no"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><p></p><h3>Final Selection</h3><ul><li><p><strong>TopKScoreSelector</strong>: sorts by score, selects top 25&#8211;50</p></li><li><p><strong>BlenderSelector</strong>: interleaves ads (minimum 5 organic posts between ads, default gap of&nbsp;3)</p></li></ul><p></p><h3>Author Diversity Decay</h3><p>Penalty for the same author appearing repeatedly in the feed: </p><p>multiplier = (1 - FLOOR) &#215; DECAY^position + FLOOR</p><ul><li><p>DECAY &#8776; 0.6&#8211;0.9 &#8594; the 2nd post from the same author is worth ~60% of the original score</p></li><li><p>FLOOR &#8776; 0.2&#8211;0.4 &#8594; never drops below this minimum</p></li></ul><p></p><h3>On language/location (from the specific search)</h3><ul><li><p><strong>language_code</strong> exists on both posts and users</p></li><li><p><strong>country_code</strong> and <strong>ip_location</strong> are also captured</p></li><li><p>No explicit filter or penalty for language mismatch &#8212; it is a feature passed to the model</p></li><li><p>The model learns language preferences implicitly from engagement history</p></li><li><p>No references to any specific locale in the scoring code</p></li></ul><p></p><h3>Identified numeric values</h3><div id="datawrapper-iframe" class="datawrapper-wrap outer" data-attrs="{&quot;url&quot;:&quot;https://datawrapper.dwcdn.net/o3H1R/1/&quot;,&quot;thumbnail_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c53030e5-484d-473d-ab11-f50d59d3596a_1220x836.png&quot;,&quot;thumbnail_url_full&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f6f0993-297e-4590-b01e-84b66d3d6ee6_1220x836.png&quot;,&quot;height&quot;:408,&quot;title&quot;:&quot;Created with Datawrapper&quot;,&quot;description&quot;:&quot;&quot;}" data-component-name="DatawrapperToDOM"><iframe id="iframe-datawrapper" class="datawrapper-iframe" src="https://datawrapper.dwcdn.net/o3H1R/1/" width="730" height="408" frameborder="0" scrolling="no"></iframe><script type="text/javascript">!function(){"use strict";window.addEventListener("message",(function(e){if(void 0!==e.data["datawrapper-height"]){var t=document.querySelectorAll("iframe");for(var a in e.data["datawrapper-height"])for(var r=0;r<t.length;r++){if(t[r].contentWindow===e.source)t[r].style.height=e.data["datawrapper-height"][a]+"px"}}}))}();</script></div><h2>Examples</h2><p>Now that we have all this information, I asked Claude Code to create an HTML file with some examples of posts that could went viral based in the new algorithm. Below is the result.</p><h3>Open questions (maximise replies)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KJXR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KJXR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png 424w, https://substackcdn.com/image/fetch/$s_!KJXR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png 848w, https://substackcdn.com/image/fetch/$s_!KJXR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png 1272w, https://substackcdn.com/image/fetch/$s_!KJXR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KJXR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png" width="1456" height="1156" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1156,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:304488,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.nelsonlopes.net/i/198153029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KJXR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png 424w, https://substackcdn.com/image/fetch/$s_!KJXR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png 848w, https://substackcdn.com/image/fetch/$s_!KJXR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png 1272w, https://substackcdn.com/image/fetch/$s_!KJXR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373bc508-913f-4d2c-a1f7-87c639e550fc_1476x1172.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Hot takes and strong opinions (generate debate)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d8am!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d8am!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png 424w, https://substackcdn.com/image/fetch/$s_!d8am!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png 848w, https://substackcdn.com/image/fetch/$s_!d8am!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png 1272w, https://substackcdn.com/image/fetch/$s_!d8am!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d8am!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png" width="1456" height="1255" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1255,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:338353,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.nelsonlopes.net/i/198153029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!d8am!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png 424w, https://substackcdn.com/image/fetch/$s_!d8am!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png 848w, https://substackcdn.com/image/fetch/$s_!d8am!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png 1272w, https://substackcdn.com/image/fetch/$s_!d8am!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15fd9258-3fb5-4c18-a212-02c58cab6b4a_1466x1264.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Educational threads (maximise dwell time and follows)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HWRl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HWRl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png 424w, https://substackcdn.com/image/fetch/$s_!HWRl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png 848w, https://substackcdn.com/image/fetch/$s_!HWRl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png 1272w, https://substackcdn.com/image/fetch/$s_!HWRl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HWRl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png" width="1456" height="1297" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1297,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:371016,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.nelsonlopes.net/i/198153029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HWRl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png 424w, https://substackcdn.com/image/fetch/$s_!HWRl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png 848w, https://substackcdn.com/image/fetch/$s_!HWRl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png 1272w, https://substackcdn.com/image/fetch/$s_!HWRl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F469c9c18-8b6f-47a4-8567-19c3431f0140_1468x1308.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Posts with media (activate has_media + VQV_WEIGHT)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6C_f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6C_f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png 424w, https://substackcdn.com/image/fetch/$s_!6C_f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png 848w, https://substackcdn.com/image/fetch/$s_!6C_f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png 1272w, https://substackcdn.com/image/fetch/$s_!6C_f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6C_f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png" width="1456" height="964" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:964,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:636196,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.nelsonlopes.net/i/198153029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6C_f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png 424w, https://substackcdn.com/image/fetch/$s_!6C_f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png 848w, https://substackcdn.com/image/fetch/$s_!6C_f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png 1272w, https://substackcdn.com/image/fetch/$s_!6C_f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a395f03-1a35-4160-b04a-ded1e97f94d5_2002x1326.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>"Send this to someone" (maximise SHARE_VIA_DM_WEIGHT)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gA9S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gA9S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png 424w, https://substackcdn.com/image/fetch/$s_!gA9S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png 848w, https://substackcdn.com/image/fetch/$s_!gA9S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png 1272w, https://substackcdn.com/image/fetch/$s_!gA9S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gA9S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png" width="1456" height="1298" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1298,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:338672,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.nelsonlopes.net/i/198153029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gA9S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png 424w, https://substackcdn.com/image/fetch/$s_!gA9S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png 848w, https://substackcdn.com/image/fetch/$s_!gA9S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png 1272w, https://substackcdn.com/image/fetch/$s_!gA9S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8851d5b0-0e5e-493d-b1eb-122bc8dfe2aa_1470x1310.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Surprising data (maximise reposts and quotes)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N6HG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N6HG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png 424w, https://substackcdn.com/image/fetch/$s_!N6HG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png 848w, https://substackcdn.com/image/fetch/$s_!N6HG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png 1272w, https://substackcdn.com/image/fetch/$s_!N6HG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N6HG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png" width="1456" height="1339" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1339,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:350787,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.nelsonlopes.net/i/198153029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N6HG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png 424w, https://substackcdn.com/image/fetch/$s_!N6HG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png 848w, https://substackcdn.com/image/fetch/$s_!N6HG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png 1272w, https://substackcdn.com/image/fetch/$s_!N6HG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bf2ef00-8cb6-48a4-9ee6-545460867a1a_1470x1352.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Polls (generate clicks and direct engagement)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ClVw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ClVw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png 424w, https://substackcdn.com/image/fetch/$s_!ClVw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png 848w, https://substackcdn.com/image/fetch/$s_!ClVw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png 1272w, https://substackcdn.com/image/fetch/$s_!ClVw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ClVw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png" width="726" height="1232" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1232,&quot;width&quot;:726,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142008,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://newsletter.nelsonlopes.net/i/198153029?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F763f6e70-c08c-41ff-bfb0-b31737abab26_726x1232.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ClVw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png 424w, https://substackcdn.com/image/fetch/$s_!ClVw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png 848w, https://substackcdn.com/image/fetch/$s_!ClVw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png 1272w, https://substackcdn.com/image/fetch/$s_!ClVw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82778254-8b50-4cbe-a8d5-09f9aa55003f_726x1232.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Conclusion</h2><p>In this article I used Claude Code to analyze X&#8217;s new For You page algorithm.</p><p>And yes&#8230; I did have that moment of doubt: <em>should I have used Grok instead, since the code is from xAI?</em></p><p>In the end, I figured using an external tool might actually make the analysis more impartial &#128513;</p><p>Anyway, don&#8217;t take everything in this post as absolute truth. It was analyzed with AI, and as we all know, AI can make mistakes.</p><p>I went through the Claude Code analysis and shared several examples that you can use as inspiration for your own posts.</p><p>You can also use Claude Code (or any other AI tool) to help you create posts that are more likely to perform well under the new algorithm.</p><p>That said, in my opinion, it&#8217;s crucial not to lose your authenticity. I personally prefer to stay authentic rather than purely chasing the algorithm - but that doesn&#8217;t mean we shouldn&#8217;t study it, learn from it, and adapt our content accordingly.</p><p>Now go post on X and good luck! I hope one of your posts goes viral &#128293;</p><p>See you soon,<br>Nelson</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Não deixes que te vejam, tapa a tua câmara]]></title><description><![CDATA[Software espi&#227;o pode ser instalado nos teus dispositivos sem que d&#234;s conta, mas com este simples controlo, tudo o que v&#227;o ver &#233; escurid&#227;o]]></description><link>https://newsletter.nelsonlopes.net/p/nao-deixes-que-te-vejam-tapa-a-tua-camara</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/nao-deixes-que-te-vejam-tapa-a-tua-camara</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 05 May 2026 08:01:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CJ7q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Imagina o seguinte cen&#225;rio: est&#225;s no conforto da tua casa, a relaxar no sof&#225; ou na cama, enquanto l&#234;s um bom livro ou v&#234;s a tua s&#233;rie favorita, cozinhas ou at&#233; a fazer algo mais privado. Algures num local remoto, algu&#233;m est&#225; a ver-te atrav&#233;s da c&#226;mara de um dos teus dispositivos.</p><p>Parece paran&#243;ia, mas acontece com frequ&#234;ncia e mais facilmente do que possas pensar.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscrever&quot;,&quot;language&quot;:&quot;pt&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Obrigado por leres! Subscreve gratuitamente para receberes novos posts e apoiares o meu trabalho.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digite o seu e-mail..." tabindex="-1"><input type="submit" class="button primary" value="Subscrever"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>E o pior &#233; que n&#227;o d&#225;s conta. N&#227;o sabes que te est&#227;o a ver.</p><h2>De que forma pode acontecer este ataque?</h2><p>Pode acontecer quando descarregas ficheiros de sites que pensas serem de confian&#231;a, quando algu&#233;m se intromete entre ti e o site leg&#237;timo (um ataque conhecido como man-in-the-middle) e te entrega uma vers&#227;o adulterada do ficheiro em vez da original, ao abrires um anexo que te &#233; enviado num email, enquanto sacas torrents, quando inseres no teu computador aquela PEN que algu&#233;m te d&#225; para te passar um ficheiro e que, na verdade, &#233; malware.</p><p>Tamb&#233;m se algu&#233;m conseguir explorar alguma vulnerabilidade que o teu dispositivo tenha, seja ao n&#237;vel do sistema operativo ou das aplica&#231;&#245;es instaladas.</p><p>Pode ocorrer quando algu&#233;m mal intencionado tem acesso f&#237;sico ao teu dispositivo, nem que seja apenas por alguns minutos.</p><p>Ou simplesmente aquela aplica&#231;&#227;o que, apesar de n&#227;o precisar de acesso &#224; c&#226;mara, pede essa permiss&#227;o.</p><h2>Quem perpetua o ataque?</h2><p>As motiva&#231;&#245;es podem ser v&#225;rias: desde mera curiosidade, &#224; vontade de te espiar, ou ao desejo de te apanhar desprevenido(a) para tirar screenshots ou gravar v&#237;deos comprometedores, que mais tarde possam ser usados para te extorquir - exigindo compensa&#231;&#245;es financeiras em troca da n&#227;o partilha das imagens com pessoas tuas conhecidas ou na Internet.</p><h2>Como nos podemos proteger?</h2><p>Antes de irmos para a prote&#231;&#227;o que &#233; o motivo deste artigo, h&#225; alguns cuidados b&#225;sicos e essenciais que ajudam a dificultar estes acessos indevidos:</p><ul><li><p>Manteres o sistema operativo atualizado, instalando os updates assim que ficam dispon&#237;veis - normalmente as atualiza&#231;&#245;es introduzem novas funcionalidades mas tamb&#233;m corrigem vulnerabilidades;</p></li><li><p>Manteres as aplica&#231;&#245;es atualizadas;</p></li><li><p>Teres um antiv&#237;rus ou, preferencialmente, EDR instalado e atualizado;</p></li><li><p>Desligares ou reiniciares os teus dispositivos frequentemente;</p></li><li><p>N&#227;o cederes o teu dispositivo a ningu&#233;m, mesmo que por pouco tempo, especialmente se a pessoa n&#227;o te for pr&#243;xima;</p></li><li><p>Configurares bloqueio de ecr&#227; - por exemplo, com impress&#227;o digital;</p></li><li><p>Configurares o ecr&#227; para bloquear passados x segundos - para que bloqueie rapidamente se o pousares e te ausentares, sendo assim necess&#225;ria a impress&#227;o digital para o desbloquear se algu&#233;m lhe mexer sem o teu conhecimento.</p></li></ul><p>Contudo, a prote&#231;&#227;o que n&#227;o falha quando todas as outras falham, &#233; o <strong>bloqueador f&#237;sico de c&#226;mara</strong>. &#201; dos controlos mais efetivos que conhe&#231;o, n&#227;o exige conhecimentos t&#233;cnicos e &#233; muito barato de adquirir.</p><p>Ao contr&#225;rio dos mic lockers, ou bloqueadores de microfone, sobre os quais escrevi <a href="https://newsletter.nelsonlopes.net/p/stop-your-devices-from-listening-why-microphone-blockers-matter">aqui</a> e que t&#234;m um papel semelhante mas para bloquearem a escuta n&#227;o autorizada, simulando que s&#227;o um microfone e fazendo o dispositivo alterar automaticamente o canal de entrada para eles, mas que na verdade n&#227;o t&#234;m microfone, sendo muito efetivos contra malware que fica &#224; escuta (ou seja, do lado de l&#225; ouve-se sil&#234;ncio), mas que s&#227;o contorn&#225;veis se o atacante se aperceber do bloqueador e tiver acesso a executar comandos no dispositivo, alterando o canal de entrada para o micro do dispositivo, no caso das c&#226;maras isto n&#227;o &#233; t&#227;o &#250;til, porque mesmo que altere para a c&#226;mara de tr&#225;s, como os dispositivos passam grande parte do dia e da noite pousados, o ganho seria muito reduzido.</p><p>Os bloqueadores da c&#226;mara podem ser aplicados em computadores, tablets e smartphones. Alguns dos dispositivos mais recentes j&#225; os trazem embutidos. Quando este n&#227;o &#233; o caso, h&#225; quem cole post-its &#224; frente da c&#226;mara, ou quem (como eu) compre uma pe&#231;a pr&#243;pria que se cola por cima da c&#226;mara.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CJ7q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CJ7q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CJ7q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CJ7q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CJ7q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CJ7q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg" width="679" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:679,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Bloqueador de c&#226;mara&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Bloqueador de c&#226;mara" title="Bloqueador de c&#226;mara" srcset="https://substackcdn.com/image/fetch/$s_!CJ7q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CJ7q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CJ7q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CJ7q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71137b06-7438-4421-8aa0-cf05e7aac1a2_679x720.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Bloqueador de c&#226;mara. Foto de <a href="https://www.amazon.es/dp/B089R3L219?ref=ppx_yo2ov_dt_b_fed_asin_title">https://www.amazon.es/dp/B089R3L219?ref=ppx_yo2ov_dt_b_fed_asin_title</a></figcaption></figure></div><p>Sempre que se pretende utilizar a c&#226;mara, move-se a parte deslizante da pe&#231;a para o lado, expondo a c&#226;mara. Quando se termina de fazer uma v&#237;deochamada ou de tirar uma selfie, volta-se a deslizar para a posi&#231;&#227;o em que a c&#226;mara fica tapada. Se a pessoa for mais descuidada e n&#227;o tapar a c&#226;mara, ou se preferir desbloquear o dispositivo com a face em vez de com a impress&#227;o digital e, por isso, a mantenha destapada para n&#227;o estar sempre a tapar e a destapar, ent&#227;o o controlo deixa de ser efetivo.</p><p>Por ser um controlo f&#237;sico que se sobrep&#245;e aos controlos digitais que possam existir no dispositivo, &#233; muito efetivo, pois se esses controlos falharem ou forem comprometidos, a barreira f&#237;sica n&#227;o vai deixar que os malfeitores atinjam o seu objetivo.</p><p>Para testar, basta utilizar a aplica&#231;&#227;o da c&#226;mara ou fazer uma v&#237;deochamada com algu&#233;m, e deslizar o bloqueador para a frente da c&#226;mara. Se tudo o que visualizar for escurid&#227;o, est&#225; a funcionar bem.</p><p>E claro, n&#227;o se esque&#231;a de estender a prote&#231;&#227;o a familiares e amigos.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscrever&quot;,&quot;language&quot;:&quot;pt&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Obrigado por leres! Subscreve gratuitamente para receberes novos posts e apoiares o meu trabalho.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digite o seu e-mail..." tabindex="-1"><input type="submit" class="button primary" value="Subscrever"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Hidden Cost of the AI Boom]]></title><description><![CDATA[From delayed proposals to rising hardware prices: how chip manufacturers' focus on AI Datacenters is reshaping IT procurement]]></description><link>https://newsletter.nelsonlopes.net/p/the-hidden-cost-of-the-ai-boom</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/the-hidden-cost-of-the-ai-boom</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 16 Dec 2025 09:01:50 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Today I was informed by a supplier that the market is undergoing significant changes that may lead to delays in price approvals and supply, as well as increased technology costs.</p><p>What he says is that chip manufacturers, such as Nvidia and others, are prioritizing the supply of chips to Artificial Intelligence Datacenters, at the expense of other supplies, such as computers, multifunction printers, and other devices.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="6028" height="4012" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:4012,&quot;width&quot;:6028,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Person holding computer cell processor&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Person holding computer cell processor" title="Person holding computer cell processor" srcset="https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1494083306499-e22e4a457632?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxtaWNyb2NoaXBzfGVufDB8fHx8MTc2NTYzNTAzMXww&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@briankost">Brian Kostiuk</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><p>According to him, it is expected that this situation will continue throughout <strong>2026 and 2027</strong>, and that it will <strong>only normalize in 2028</strong>.</p><p>Which will, in every respect, be similar to what was experienced during the pandemic.</p><h2>What happened during the pandemic?</h2><p>During the Covid-19 pandemic, there were several delays. Some companies, due to a shortage of computers, had to provide computers with i3 processors to administrators - something that would normally be unthinkable, but had to be done, as the alternative was having no computers at all.</p><p>I recall that at <a href="https://www.expressglass.pt">ExpressGlass</a>, it was during this phase that, for some time, we stopped purchasing from our usual suppliers and started getting computers from retail stores - basically anywhere we could find them - deviating from our usual and more professional models. This was how we resolved the situation. When stock was available, it was picked up immediately and the issue was resolved.</p><p>We felt the impact on computers, but the most concerning issue was with the toners for the Xerox multifunction printers.</p><p>Those were very worrying times because we still didn&#8217;t have electronic invoicing, so shipments from <a href="https://www.axial.pt">DiverAxial</a> were required to go out with an invoice.</p><p>It was illegal for the carriers to make deliveries without the invoices, even if they had already been issued in the system. The carriers themselves wouldn&#8217;t even accept doing it. If they were stopped by the authorities and didn&#8217;t have the invoice, a fine would be imposed.</p><p>This put the entire operation and business of ExpressGlass at risk, since DiverAxial is its main supplier.</p><p>Therefore, at the time, it was necessary to source toners from various places. Coordinating all of this was not easy. We filed complaints and requested stock, but there simply wasn&#8217;t any. During this phase, the truth is that we faced significant risks.</p><h2>Reality or speculation?</h2><p>It is still being determined whether this will become a reality or if it is mere speculation. But the fact is that several delays are already occurring, particularly in the approval of prices and proposals.</p><p>The supplier even shared that they have already experienced a 70% increase, and since they have a supply contract, they are actually being heavily penalized.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The 3 Essential Steps Before Starting to Resolve Incidents]]></title><description><![CDATA[Turn Chaos into Structured and Predictable Incident Management]]></description><link>https://newsletter.nelsonlopes.net/p/the-3-essential-steps-before-starting-to-resolve-incidents</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/the-3-essential-steps-before-starting-to-resolve-incidents</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 18 Nov 2025 13:02:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Y-Rq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If managing incidents on its own can be stressful, imagine doing it without any organization. </p><p>Depending on the volume of incoming requests and their severity, chaos can quickly take over. From having no visibility into the number of requests hitting the incident response teams, to being unaware of the biggest problem hotspots, or even having technicians resolving non-urgent, low-impact issues while critical ones sit in the queue.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Follow these steps to make your day-to-day operations smoother.</p><h2>Steps in Incident Management</h2><p>There are <strong>three essential minimum steps</strong> for proper incident management.</p><h3>Step 1: Log the Incident</h3><p>The first step every technician must be instructed on is that <strong>an incident does not exist unless it is logged</strong>. For that, the ideal scenario is to have a ticketing platform that users are familiar with - everyone should receive training on it when it is implemented, and it should also be part of the onboarding training plan for new employees.</p><p>I won&#8217;t go into the topic of who should open the ticket, but in case you define it should be the user, be careful with agents who kindly open tickets on behalf of users - these cases are easy to notice in day-to-day operations, but the manager should regularly review the platform&#8217;s statistics to understand the scale of the problem. These &#8220;kind gestures&#8221; can undermine years of user education aimed at getting them to open tickets instead of approaching technicians directly.</p><p>If users have other communication channels to reach technicians and can initiate incident reporting that way, I still maintain that the incident must be logged - therefore someone has to create the ticket. In this case, it should be the technicians. The biggest challenge is getting technicians to create the ticket before starting the analysis and resolving the issue, so they don&#8217;t forget or get lazy to do it later.</p><p>In both scenarios, in less mature teams, it is common to see numerous issues solved without a ticket. This means that at the end of the day (or at the end of the month or year in accumulation), the statistics will not reflect the actual number of incidents that occurred, the real Mean Time to Resolve (MTTR), the number of incidents by category, nor the hours the team truly dedicated to this area.</p><h3>Step 2: Categorize the Incident</h3><p>Once logged, the incident must be categorized. Categorization helps assign the incident to the appropriate support team and also allows reporting to show which categories are becoming the most problematic.</p><p>Creating categories in a support tool is something that should be carefully considered and, like everything else, should evolve over time. What I mean by this is that it&#8217;s normal to have doubts about the structure you&#8217;re going to implement - whether it should have two levels (category and subcategory) or three (category, subcategory, and item), whether it should be specific enough to include modules within a particular application, or kept more generic.</p><p>There is no single &#8220;correct&#8221; way to implement categories. Each organization should think about what works best for them. However, based on my experience, the trend has been to simplify - meaning simplify both for users and for technicians. But only by analyzing the data can you properly assess whether this simplification limits management&#8217;s ability to understand where most problems are occurring, or where the most critical issues for the organization lie, and where time should be invested to address them.</p><h3>Step 3: Prioritize the Incident</h3><p>Once the incident is categorized, its priority must be defined among all the other unresolved tickets.</p><p>The priority of a ticket is determined by impact vs. urgency. This means there should be a scale for impact, another for urgency, and a matrix that clearly indicates the priority based on these two variables.</p><p>Personally, I like using the matrix provided by <a href="https://affiliatepartner-freshservice.freshworks.com/incident-management">Freshservice</a> (this is an affiliate link - if you sign up, I may earn a small commission at no additional cost to you):</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y-Rq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png 424w, https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png 848w, https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png 1272w, https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png" width="815" height="302" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/afd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:302,&quot;width&quot;:815,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:26660,&quot;alt&quot;:&quot;Freshservice default priority matrix&quot;,&quot;title&quot;:&quot;Uma matriz de prioridade, atrav&#233;s do impacto versus urg&#234;ncia&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Freshservice default priority matrix" title="Uma matriz de prioridade, atrav&#233;s do impacto versus urg&#234;ncia" srcset="https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png 424w, https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png 848w, https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png 1272w, https://substackcdn.com/image/fetch/$s_!Y-Rq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fafd41c04-1191-4bf7-9a26-b8cd9abab834_815x302.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Freshservice&#8217;s default priority matrix</figcaption></figure></div><p>On the X-axis we have urgency, and on the Y-axis we have impact. By classifying both, we obtain the priority that should be assigned to the ticket.</p><p>Of course, even after defining the priority, it may still match the priority of other incidents awaiting resolution. That&#8217;s where experience and business knowledge come into play.</p><p>Technicians with more years in the organization will intuitively know which tickets should take precedence - it will vary from case to case, but having alignment with leadership is ideal.</p><p>Less experienced technicians should rely on their colleagues or, ideally, their manager to understand which issues they should tackle first.</p><h2>Conclusion</h2><p>Incident Management only works when the fundamentals are in place: every incident must be logged, properly categorized, and prioritized based on impact and urgency. These practices may seem simple, but they form the backbone of an efficient and mature support organization.</p><p>By applying these three steps consistently, teams gain clearer visibility of their workload, reduce resolution times, improve communication with users, and build a reliable dataset to support better decision-making.</p><p>Improving Incident Management is a continuous journey - not a one-time project. Start with the basics, adapt the process to your organization, and refine it over time. Small improvements, applied consistently, lead to meaningful long-term results.</p><p>If you already follow these practices or have additional recommendations, feel free to share your experience in the comments.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Stop your devices from listening: why microphone blockers matter]]></title><description><![CDATA[Even when you think your gadgets are silent, they might still be listening. Here&#8217;s how a simple plug can protect your privacy.]]></description><link>https://newsletter.nelsonlopes.net/p/stop-your-devices-from-listening-why-microphone-blockers-matter</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/stop-your-devices-from-listening-why-microphone-blockers-matter</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Fri, 10 Oct 2025 20:56:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!yCCB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If, like me, you dislike being listened to without your consent or awareness, then this article is for you. Learn why you should use microphone blockers.</p><p>Imagine being in the comfort of your home, having conversations with your partner, children, and other family members, while someone is remotely listening in through your devices.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>It&#8217;s not a very pleasant situation, is it? I don&#8217;t think anyone would like that.</p><p>That&#8217;s why it&#8217;s important to take precautions to ensure that these types of situations don&#8217;t happen.</p><p>Typically, operating systems aim to protect their users from such attacks. However, the best protection always lies in combining software controls with hardware controls, meaning&#8230;</p><ul><li><p>Keeping the operating system and applications up to date;</p></li><li><p>Regularly reviewing application permissions;</p></li><li><p>Having an antivirus installed and kept up to date.</p></li></ul><p>All of this helps protect against such threats, but it doesn&#8217;t guarantee that it won&#8217;t happen.</p><p>Therefore, the ideal solution is to use a microphone blocker, which will route the audio from your device to the blocker itself and receive audio back from it. In other words, your device will think a headset, for example, has been plugged in, so the device&#8217;s microphone is disabled, and the supposed microphone from the adapter is activated. However, this adapter does not have a built-in microphone, so it does not send any audio back to your device. This way, everything the other side hears, if someone is listening, is silence.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yCCB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yCCB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yCCB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yCCB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yCCB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yCCB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg" width="1200" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;A microphone blocker inserted into a laptop&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A microphone blocker inserted into a laptop" title="A microphone blocker inserted into a laptop" srcset="https://substackcdn.com/image/fetch/$s_!yCCB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!yCCB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!yCCB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!yCCB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F21d4846f-12bb-44f9-b1a5-6375317c0473_1200x1200.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A microphone blocker by Mic-Lock</figcaption></figure></div><p>I recommend the microphone blockers from <a href="https://mic-lock.com">Mic-Lock</a>. I personally use them on both my computer and smartphone, and they work very well.</p><p>You can test it by using a recording app to record an audio clip without the adapter and then with the adapter. When you listen to the recording later, you&#8217;ll notice that from the moment the adapter is inserted, no sound is recorded. The app continues recording, but there&#8217;s no audio input, which is exactly what we want.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[October is Cybersecurity Awareness Month]]></title><description><![CDATA[Since 2004, October has been recognized as Cybersecurity Awareness Month. This month was declared by the then President of the United States and Congress with the goal of having the public and private sectors work together to raise awareness about the importance of cybersecurity.]]></description><link>https://newsletter.nelsonlopes.net/p/october-is-cybersecurity-awareness-month</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/october-is-cybersecurity-awareness-month</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Wed, 01 Oct 2025 19:42:34 GMT</pubDate><enclosure url="https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h3>History and Origins of Cybersecurity Month</h3><h4>United States of America</h4><p>Since 2004, October has been recognized as <a href="https://www.cisa.gov/cybersecurity-awareness-month">Cybersecurity Awareness Month</a>. This month was declared by the then President of the United States and Congress with the goal of having the public and private sectors work together to raise awareness about the importance of cybersecurity.</p><p>This initiative has gained importance over the years, with efforts between government and industry to reduce online risks and generate discussion about cyber threats on a national scale in the United States, as well as globally.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In 2023, the <a href="https://www.cisa.gov">Cybersecurity &amp; Infrastructure Security Agency (CISA)</a> launched its awareness program called <a href="https://www.cisa.gov/secure-our-world">Secure Our World</a>, which recognizes the importance of taking daily actions to reduce online risks and the risks of using connected devices. It also enables organizations to use this theme when preparing for Cybersecurity Awareness Month, that is, when preparing their own awareness campaigns.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw"><img src="https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080" width="7952" height="5304" data-attrs="{&quot;src&quot;:&quot;https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:5304,&quot;width&quot;:7952,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;red padlock on black computer keyboard&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="red padlock on black computer keyboard" title="red padlock on black computer keyboard" srcset="https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 424w, https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 848w, https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1272w, https://images.unsplash.com/photo-1614064642261-3ccbfafa481b?crop=entropy&amp;cs=tinysrgb&amp;fit=max&amp;fm=jpg&amp;ixid=M3wzMDAzMzh8MHwxfHNlYXJjaHw0fHxjeWJlcnNlY3VyaXR5JTIwbW9udGh8ZW58MHx8fHwxNzU5MzQ2ODYzfDA&amp;ixlib=rb-4.1.0&amp;q=80&amp;w=1080 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Photo by <a href="https://unsplash.com/@flyd2069">FlyD</a> on <a href="https://unsplash.com">Unsplash</a></figcaption></figure></div><h4>Europe</h4><p>On the European side, <a href="https://www.enisa.europa.eu/topics/awareness-and-cyber-hygiene/european-cybersecurity-month">European Cybersecurity Month</a> is the European Union (EU) campaign dedicated to promoting cybersecurity among European citizens and organizations, as well as providing updated information related to online security and sharing best practices.</p><p>Every year, throughout the entire month of October, hundreds of activities take place across Europe, including conferences, workshops, training sessions, webinars, presentations, and more, aimed at promoting digital security and cybersecurity hygiene.</p><p>This initiative is coordinated by the <a href="https://www.enisa.europa.eu">European Union Agency for Cybersecurity (ENISA)</a> and the European Commission, and is supported by each Member State and hundreds of government partners, including universities, think tanks, Non-Governmental Organizations (NGOs), professional associations, and the private sector in Europe and beyond.</p><p>Since the first event in 2012, European Cybersecurity Month has been promoted under the slogan &#8220;Cybersecurity is a Shared Responsibility&#8221; and, in 2020, the motto &#8220;Think Before U Click!&#8221; was officially launched.</p><h3>And the rest of the year?</h3><p>Although October is considered Cybersecurity Awareness Month, we must not forget that cybersecurity is something we should be concerned about every other month. I would go further: daily, throughout the entire year.</p><p>These are government initiatives, both in the United States and Europe, aimed at creating a period, at least once a year, during which various initiatives are held to raise cybersecurity awareness. However, all individuals and businesses should be aware that it&#8217;s not just during this month that they should focus on and invest in cybersecurity, but throughout the entire year.</p><p>Attacks do not happen only in October, but throughout the entire year. Therefore, it is important that people progressively protect themselves more over the year and across the years, implementing more controls that ensure their networks, devices, and accounts are progressively more secure.</p><h3>Companies, schools, and other organizations</h3><p>This can be an opportunity for companies, schools, and other organizations to join this initiative and also use the month of October to promote cybersecurity. This doesn&#8217;t require a great effort, as much of the material already exists and there can simply be a sharing plan in place.</p><p>This doesn&#8217;t mean that throughout the rest of the year there isn&#8217;t a need to continue raising awareness on this topic, but the month of October can be used for greater dissemination by entities, taking advantage of all the support provided by governments and other organizations for online promotion. This also allows for sharing various best practices, information about attacks, and how to protect oneself.</p><h3>How to learn more</h3><p>Anyone interested in following this topic more closely and learning more can visit the following websites:</p><ul><li><p><a href="https://www.cisa.gov/cybersecurity-awareness-month">Cybersecurity Awareness Month</a> by CISA;</p></li><li><p><a href="https://www.cisa.gov/secure-our-world">Secure Our World</a>;</p></li><li><p><a href="https://www.enisa.europa.eu/topics/awareness-and-cyber-hygiene/european-cybersecurity-month">European Cybersecurity Month</a> by ENISA;</p></li><li><p><a href="https://cybersecuritymonth.eu/">ECSM &#8211; European CyberSecurity Month</a>.</p></li></ul><p>In addition to these websites related to Cybersecurity Month, there is a vast array of other content you can follow, including forums, books, courses, newsletters like this one, among many others.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[LinkedIn is now feeding Microsoft's AI with your data]]></title><description><![CDATA[You have until November 3rd to opt out - consent is on by default.]]></description><link>https://newsletter.nelsonlopes.net/p/linkedin-is-now-feeding-microsofts-ai</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/linkedin-is-now-feeding-microsofts-ai</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Wed, 24 Sep 2025 22:26:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EJGR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It&#8217;s not exactly surprising - many platforms have already done it - but now LinkedIn will also start using your data to train Microsoft&#8217;s AI. <strong>By default, consent is turned on</strong>, and <strong>you have until November 3rd to switch it off</strong> if you don&#8217;t agree.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EJGR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EJGR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png 424w, https://substackcdn.com/image/fetch/$s_!EJGR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png 848w, https://substackcdn.com/image/fetch/$s_!EJGR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png 1272w, https://substackcdn.com/image/fetch/$s_!EJGR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EJGR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png" width="1456" height="390" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:390,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:131744,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://lopesnelson.substack.com/i/174370927?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EJGR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png 424w, https://substackcdn.com/image/fetch/$s_!EJGR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png 848w, https://substackcdn.com/image/fetch/$s_!EJGR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png 1272w, https://substackcdn.com/image/fetch/$s_!EJGR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97f280ca-b6dc-4e14-9b31-430ada3f660f_1478x396.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">LinkedIn update to Terms and data use</figcaption></figure></div><h3>LinkedIn update to Terms and Data Use</h3><p>Funny enough, just last weekend I was reviewing my LinkedIn settings (for no particular reason - I&#8217;ve been less active there lately and more on other platforms). To my surprise, I came across those options and immediately turned them off, wondering how I had missed this before. A few days later, I started seeing posts from others pointing out that LinkedIn was indeed updating its Terms and data use to reflect these changes.</p><p>&#128073; If you also want to opt out, go to:</p><p>Settings &gt; Data Privacy &gt; Data for Generic AI Improvement &gt; Use my data for training content creation AI models (turn it off).</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">This Substack is reader-supported. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why you need to activate Multi-Factor Authentication (MFA) immediately ]]></title><description><![CDATA[MFA helps protect your online accounts]]></description><link>https://newsletter.nelsonlopes.net/p/why-you-need-to-activate-multi-factor</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/why-you-need-to-activate-multi-factor</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Fri, 12 Sep 2025 22:02:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WZSg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>We can think of <strong>Multi-Factor Authentication (MFA)</strong> as one or more additional steps required when authenticating against a system, after entering the first factor (e.g., after entering the username and password), and before being granted access to the system.</p><p>Referring to online accounts, imagine that somehow your credentials were compromised - that is, someone managed to discover them. If you don't have MFA enabled, the attacker will be able to access your account without any difficulty. However, with MFA active, after entering the username-password combination, the attacker will be confronted with a second authentication step using a different factor.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The goal is for only the user, the true account holder, to have access to the additional factor(s) required to access the system in question. This way, in a situation like this, the account will be protected, as it will be much harder for the attacker to bypass these other factors. However, bear in mind that harder does not mean impossible.</p><h2>Authentication factors</h2><p>There are three primary authentication factors. They are:</p><ul><li><p><strong>Something you know</strong>, which can be a password, a passphrase, a PIN, the answer to security questions, etc.</p></li><li><p><strong>Something you have</strong>, which refers to physical devices in the user's possession that can help with authentication, such as a mobile phone, a smart card, a hardware token, a memory card, a USB drive, etc.</p></li><li><p><strong>Something you are</strong>, which refers to physical characteristics of a person, such as fingerprints, facial features, retina patterns, iris patterns, hand geometry, etc.</p></li></ul><p>In addition to the three primary factors, attributes such as the following can be added:</p><ul><li><p><strong>Where you are</strong>, based on a device, geographic location, a phone number, etc.</p></li><li><p><strong>Contextual authentication</strong>, where, for example, you can set working hours, not allowing access to the account outside of those hours. It can also include location and device type.</p></li><li><p><strong>Something you do</strong>, which can refer, for example, to gestures used on mobile devices to unlock them by connecting points (pattern), or image passwords, supported by Windows 10, where the user moves their fingers on the screen over an image.</p></li></ul><h2>Something you know</h2><p>This factor is also known as <strong>knowledge-based authentication</strong> or <strong>type 1 authentication factor</strong>.</p><p>It means that the user provides something they know to authenticate themselves to a system.</p><p>In the case of passwords, they can be simple or complex, where:</p><ul><li><p>Incorrectly, people tend to use simple passwords, often related to personal information, because they are easier to remember. When this happens, passwords are easily guessed.</p></li><li><p>When using complex passwords, people often end up writing them down somewhere, whether on post-it notes stuck to the monitor, in a notebook, or even in a text file on their computer&#8217;s desktop. In these cases, the password becomes visible to others, or even if it is not in plain sight, it can be found relatively easily.</p></li></ul><p>The solution to these problems lies in Password Managers, which organize your credentials, store them securely, and, best of all, you only need to remember one password - the master password, which is used to log in to the Password Manager. This master password should be long (at least 14 characters) and, to make it easier, you can create a passphrase.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WZSg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WZSg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WZSg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WZSg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WZSg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WZSg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg" width="1024" height="661" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:661,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;No Multifator de Autentica&#231;&#227;o, as passwords fazem parte do fator algo que sabe&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="No Multifator de Autentica&#231;&#227;o, as passwords fazem parte do fator algo que sabe" title="No Multifator de Autentica&#231;&#227;o, as passwords fazem parte do fator algo que sabe" srcset="https://substackcdn.com/image/fetch/$s_!WZSg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg 424w, https://substackcdn.com/image/fetch/$s_!WZSg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg 848w, https://substackcdn.com/image/fetch/$s_!WZSg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!WZSg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9d7560db-84f8-423a-b8d2-f9ae80df632e_1024x661.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">In Multi-Factor Authentication, passwords are part of the <strong>something you know</strong> factor. Credit: <a href="https://pixabay.com/users/mohamed_hassan-5229782/">Mohamed_hassan via Pixabay</a></figcaption></figure></div><p>Passphrases are passwords based on phrases, making them easier to remember, and they address the complexity issue, especially when mixed with uppercase and lowercase letters, numbers, and special characters.</p><p>Regarding security questions, their security also increases if the user uses complex strings instead of the actual answer to the questions. The true answers are often so obvious to those who know the user even slightly (and with all the information shared on social media these days, this can be relatively easy), making them easy to compromise.</p><h2>Something you have</h2><p>This factor is also known as <strong>possession-based authentication</strong> or <strong>type 2 authentication factor</strong>.</p><p>Perhaps the most common method is One-Time Passwords (OTP), which, as the name suggests, are codes that can only be used once and expire if not used within a certain period of time. They can be generated via:</p><ul><li><p><strong>Software (soft tokens)</strong>, such as the popular Authenticator apps like <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2">Google Authenticator</a>, <a href="https://play.google.com/store/apps/details?id=com.azure.authenticator">Microsoft Authenticator</a>, <a href="https://duo.com/">Cisco DUO</a>, etc.</p></li><li><p><strong>Hardware (hard tokens)</strong>, which are dedicated hardware devices, such as the <a href="https://www.rsa.com/products/securid/">RSA SecurID</a>.</p></li></ul><p>In addition to the type of device where they are generated, OTPs can be:</p><ul><li><p><strong>Synchronous OTP</strong>, which is the most common and least complex. It can be time-based or counter-based. Time-based OTPs are generated every 30 or 60 seconds, while counter-based OTPs increment a number with each use.</p></li><li><p><strong>Asynchronous OTP</strong>, which, although less common and more complex, provides a more robust layer of security.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xP_H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xP_H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif 424w, https://substackcdn.com/image/fetch/$s_!xP_H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif 848w, https://substackcdn.com/image/fetch/$s_!xP_H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif 1272w, https://substackcdn.com/image/fetch/$s_!xP_H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xP_H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif" width="1024" height="683" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:683,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;No Multifator de Autentica&#231;&#227;o, as security keys pertencem ao fator algo que tem&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="No Multifator de Autentica&#231;&#227;o, as security keys pertencem ao fator algo que tem" title="No Multifator de Autentica&#231;&#227;o, as security keys pertencem ao fator algo que tem" srcset="https://substackcdn.com/image/fetch/$s_!xP_H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif 424w, https://substackcdn.com/image/fetch/$s_!xP_H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif 848w, https://substackcdn.com/image/fetch/$s_!xP_H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif 1272w, https://substackcdn.com/image/fetch/$s_!xP_H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f255823-2e90-4cbb-a7bc-beb5015ed153_1024x683.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">In Multi-Factor Authentication, security keys belong to the <strong>something you have</strong> factor. Credit: <a href="https://www.pexels.com/@cottonbro/">Cottonbro Studio via Pexels</a></figcaption></figure></div><p>Smart cards, on the other hand, are so named because they contain an embedded integrated circuit that can perform calculations and generate unique authentication data for each transaction. They can be:</p><ul><li><p><strong>Contact Smart Cards</strong>, where the chip on the card needs to make contact with the reader to receive power and allow the transaction to be completed.</p></li><li><p><strong>Contactless Smart Cards</strong>, where the reader sends signals that are strong enough to power the chips and communicate with them, allowing the card to perform the necessary calculations and respond to the reader.</p></li></ul><p>Memory cards contain a type of memory that is embedded in a magnetic strip, usually on the back of the card, from which the same data is read during each transaction.</p><h2>Something you are</h2><p>Also known as <strong>biometric authentication</strong> or <strong>type 3 authentication factor</strong>.</p><p>It is divided into:</p><ul><li><p><strong>Physiological characteristics</strong>, which can include fingerprints, hand geometry, facial features, eye characteristics (such as iris and retina), etc.</p></li><li><p><strong>Behavioral characteristics</strong>, which can include how a person writes, walks, speaks, presses the keys on a keyboard, etc.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!quFO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!quFO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif 424w, https://substackcdn.com/image/fetch/$s_!quFO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif 848w, https://substackcdn.com/image/fetch/$s_!quFO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif 1272w, https://substackcdn.com/image/fetch/$s_!quFO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!quFO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif" width="1024" height="684" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:684,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;No Multifator de Autentica&#231;&#227;o, os leitores de impress&#245;es digitais pertencem ao fator algo que &#233;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="No Multifator de Autentica&#231;&#227;o, os leitores de impress&#245;es digitais pertencem ao fator algo que &#233;" title="No Multifator de Autentica&#231;&#227;o, os leitores de impress&#245;es digitais pertencem ao fator algo que &#233;" srcset="https://substackcdn.com/image/fetch/$s_!quFO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif 424w, https://substackcdn.com/image/fetch/$s_!quFO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif 848w, https://substackcdn.com/image/fetch/$s_!quFO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif 1272w, https://substackcdn.com/image/fetch/$s_!quFO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea9978d3-7ba0-4cf9-8215-244d24d5628f_1024x684.avif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">In Multi-Factor Authentication, fingerprint readers belong to the <strong>something you are</strong> factor. Credit: <a href="https://www.pexels.com/@cookiecutter/">Panumas Nikhomkhai via Pexels</a></figcaption></figure></div><h2>Where you are</h2><p>Location can be obtained based on the IP address or through geolocation.</p><p>This type of system can prevent access by users who are not in the location where they typically connect - <strong>where you are not</strong>. In fact, a basic rule is that a user should not be able to log in to their account outside of their workplace, or, if they wish to do so, they must request permission. Although this control can be easily bypassed using a VPN, it still serves as a protection that makes sense.</p><h2>Single-Factor Authentication and Two-Factor Authentication</h2><p>There is some confusion regarding what is considered the use of authentication factors.</p><p>For example, if a system uses more than one type of authentication, but all are from the same factor, it is not Multi-Factor Authentication, but rather <strong>Single-Factor Authentication</strong>. Examples where, despite using different types of authentication, Multi-Factor Authentication does not occur:</p><ul><li><p>The use of username/password and the answer to security questions - both mechanisms belong to the <strong>something you know</strong> factor.</p></li><li><p>The use of a token generated by Google Authenticator and another generated by RSA SecurID - both mechanisms belong to the <strong>something you have</strong> factor.</p></li><li><p>The use of a fingerprint reader and a retina reader - both mechanisms belong to the <strong>something you are</strong> factor.</p></li></ul><p>The combination of two factors, such as something you know and something you have, can be called <strong>Two-Factor Authentication</strong>.</p><p>The difference between Two-Factor Authentication and Multi-Factor Authentication is that the former refers to the use of two factors, while the latter refers to the use of two or more factors.</p><p>It is important to note that using different types of authentication from the same factor typically does not add security, as the same type of attack can compromise them. In other words, using a password and a PIN does not guarantee that you are more secure than if you only used a password, as the same attacks that can be performed to discover the password can also discover the PIN. In contrast, when using different factors, such as a password and an OTP from a hard token, it would be necessary to both discover the password and physically steal the hard token in order to successfully access the account.</p><h2>Weak and Strong Multi-Factor Authentication</h2><p>Although Multi-Factor Authentication (MFA) is a recommended configuration, it does not guarantee by itself that your accounts are secure. For example, SMS-based Multi-Factor Authentication is considered weak due to an attack known as SIM Swap, in which criminals gain control of the victim's phone number, thus gaining access to the code sent to it, enabling them to log into the victim's accounts.</p><p>However, even when using strong authentication factors, there are some considerations to keep in mind:</p><ul><li><p>When using an Authenticator that sends notifications for the user to approve access, if the user is distracted or unaware of what they are doing, they may accidentally approve access for a third party without realizing what is actually happening.</p></li><li><p>When using an Authenticator that sends notifications, generates codes, or asks for a code provided on the website, although these methods are considered secure, the user can be deceived if they access a fake website that closely resembles the real one. In such cases, the data the user enters - such as their username and password - will be sent to the real site, followed by the OTP, allowing the attacker to gain unauthorized access.</p></li></ul><p>To address this, you could consider using passkeys or even security keys (physical security keys), as these devices must be physically connected to the device from which the login is being made, or brought near (via NFC), in order for access to be granted. This adds an additional layer of security by ensuring that the attacker cannot gain access without having the physical key or device.</p><h2>Does the second authentication factor always have to be requested?</h2><p>No, not always. For example, some services only ask for it the first time you use a particular device. After that, the device is authorized to access your account and is recognized as trusted, and by itself, functions as a factor. The second factor will only be requested when you access from a device that the service does not recognize.</p><p>There are also services that allow you to store the data for a certain period of time, not requesting the second authentication factor until that period expires.</p><h2>What if I lose the MFA method?</h2><p>You should always keep in mind alternatives to the MFA method you set up. For example, some services provide backup codes that can be used in case you lose access to the configured method. Make sure to note those codes down carefully. If you are using a security key as an authentication factor, like a <a href="https://www.yubico.com/">Yubikey</a>, it is a good practice to have a second security key in case you lose the first one. You might even consider storing the second key in a different physical location than the first.</p><h2>A word about FIDO2</h2><p>I can't finish this article without mentioning <a href="https://fidoalliance.org/fido2/">Fast IDentity Online 2 (FIDO2)</a>, although in a very brief way. FIDO2 is an open protocol for user authentication that uses passkeys, which are credentials created through public key cryptography, with a private key and a public key being created. The private key is securely stored on the user's device, and the public key is encrypted and sent to the service's server.</p><p>The key pair is used to authenticate the user directly on their device, whether it&#8217;s a computer, tablet, mobile phone, or security key. Whenever the user logs in, the service presents a unique challenge to the client. The device is activated via touch, fingerprint or face recognition, or PIN entry, allowing the request to be signed and returned. This makes the process cryptographically protected against phishing.</p><p>Since a different key pair is generated for each web application or website, they also have the advantage of enhancing user privacy by making it harder to link activity across services.</p><p>FIDO2 also implements the concept of Passwordless, which means that no passwords are used to log in. This makes access not only more convenient but also more secure, as the vulnerabilities associated with passwords are well known.</p><p>The first version, which introduced phishing-resistant Multifactor Authentication, was released in 2014, and the second, released in 2018, defined the standard for passwordless authentication.</p><h2>Conclusion</h2><p>In conclusion, despite all the information in this article, the main takeaway is the importance of enabling Multifactor Authentication on all your accounts that support it - this is usually something that can be done in your account settings.</p><p>Not all services use strong MFA, but even so, having MFA enabled - even if weak - is better than having none.</p><p>Conduct an audit of your accounts now to enable MFA on those where it&#8217;s not yet activated. It&#8217;s true that it will take some time, but in the end, you&#8217;ll feel more at ease about the security of your accounts and the information they contain.</p><p>Thinking that it only happens to others is not a good security strategy. It&#8217;s also important to keep in mind that there are various ways credentials can be compromised, whether through attacks targeting the user directly or the service where their credentials are stored. And we don&#8217;t always know how these services handle our data - in other words, there have been numerous leaks showing that some services still don&#8217;t follow best practices for storing their users&#8217; credentials!</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Did you know you can connect a keyboard and mouse to your smartphone or tablet?]]></title><description><![CDATA[And to the TV box?]]></description><link>https://newsletter.nelsonlopes.net/p/did-you-know-you-can-connect-a-keyboard</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/did-you-know-you-can-connect-a-keyboard</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 09 Sep 2025 22:27:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PVX1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Your keyboard and mouse can be connected to your smartphone or tablet to improve the user experience of these devices.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PVX1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PVX1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PVX1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PVX1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PVX1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PVX1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg" width="1600" height="1036" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1036,&quot;width&quot;:1600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:495098,&quot;alt&quot;:&quot;A smartphone with a keyboard and a mouse connected&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://nelsonlopesen.substack.com/i/173222842?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea773478-4271-4011-b58e-086f1c65713f_1600x1200.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A smartphone with a keyboard and a mouse connected" title="A smartphone with a keyboard and a mouse connected" srcset="https://substackcdn.com/image/fetch/$s_!PVX1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PVX1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PVX1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PVX1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffcaf7e22-b31a-4c69-be96-e5d1f88e41b6_1600x1036.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A smartphone with a keyboard and a mouse connected</figcaption></figure></div><p>I don&#8217;t know if this is the case for everyone, but I type faster on a physical keyboard than on a virtual one like those on mobile devices. So, for longer texts or extended conversations, using a physical keyboard can be quite useful.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Nelson Lopes [EN]! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The same goes for the mouse, which can be used in various applications, including games.</p><p>For this to be possible, you may need a USB-A to USB-C adapter.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qZkQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qZkQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qZkQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qZkQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qZkQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qZkQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg" width="1456" height="1089" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1089,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1527590,&quot;alt&quot;:&quot;A USB-A to USB-C adapter&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://nelsonlopespt.substack.com/i/173219627?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A USB-A to USB-C adapter" title="A USB-A to USB-C adapter" srcset="https://substackcdn.com/image/fetch/$s_!qZkQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qZkQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qZkQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qZkQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c89425d-078f-405b-89bf-b84addbb9a98_4640x3472.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A USB-A to USB-C adapter</figcaption></figure></div><p>To further improve the experience, you can place the device on a dedicated stand in front of you, either horizontally or vertically, so the screen faces you without having to hold it in your hand or lay it flat on the table.</p><p>In addition to mobile devices, they can also be connected to your TV box. This makes its use much easier, since, for example, searching on YouTube with the box&#8217;s remote is&#8230; time-consuming!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QbeL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QbeL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QbeL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QbeL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QbeL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QbeL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg" width="1456" height="1089" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1089,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1110777,&quot;alt&quot;:&quot;Using a physical keyboard to search YouTube on a TV box&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://nelsonlopesen.substack.com/i/173222842?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Using a physical keyboard to search YouTube on a TV box" title="Using a physical keyboard to search YouTube on a TV box" srcset="https://substackcdn.com/image/fetch/$s_!QbeL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QbeL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QbeL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QbeL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F936f3c9e-7d40-4237-a5c2-144d291f27dd_4640x3472.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Using a physical keyboard to search YouTube on a TV box</figcaption></figure></div><p>Did you already know about this? Have you ever connected a keyboard and/or mouse to mobile devices or TV boxes? What was the purpose? Share your experience in the comments.</p><p>See you soon,</p><p>Nelson Lopes</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Nelson Lopes [EN]! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Slow network and it’s Tuesday?]]></title><description><![CDATA[And is it specifically the second Tuesday of the month?]]></description><link>https://newsletter.nelsonlopes.net/p/slow-network-and-its-tuesday</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/slow-network-and-its-tuesday</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 12 Aug 2025 08:01:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0dzk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>It&#8217;s called <strong>Patch Tuesday</strong>, and it&#8217;s the day Microsoft releases updates for its products. Depending on the size of your device fleet and the bandwidth available, you might notice some network slowness on these days - especially if there&#8217;s no structured update management policy in place.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0dzk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0dzk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0dzk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0dzk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0dzk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0dzk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2240459,&quot;alt&quot;:&quot;A woman waiting for the computer to unblock.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://lopesnelson.substack.com/i/170075670?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A woman waiting for the computer to unblock." title="A woman waiting for the computer to unblock." srcset="https://substackcdn.com/image/fetch/$s_!0dzk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0dzk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0dzk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0dzk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F421ef434-12d5-47ef-a273-a030c4292349_6000x4000.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Waiting is hard.</figcaption></figure></div><p>On this day, Microsoft rolls out critical patches (including zero-days), security updates, cumulative updates, bug fixes, and performance/stability improvements.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Nelson Lopes [EN] is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In enterprise environments, don&#8217;t forget to manage updates carefully: test them on staging machines first, and only then roll them out to the rest of the organization. In fact, I recommend using a <strong>three-ring approach</strong>:</p><ul><li><p><strong>Ring 0</strong> &#8211; First machines and users to receive updates;</p></li><li><p><strong>Ring 1</strong> &#8211; Key machines/users representing different departments;</p></li><li><p><strong>Ring 2</strong> &#8211; The rest of the organization.</p></li></ul><p>This can be managed using solutions like Intune, WSUS, SCCM, or other remote management platforms (RMMs).</p><p>That said, patches that fix zero-days - vulnerabilities for which no official fix existed and that may already be exploited - should be applied as early as possible, regardless of which ring the device belongs to.</p><p>Also, keep in mind: if the second Tuesday of the month is a public holiday, it&#8217;s likely that many computers were off and didn&#8217;t receive the update - meaning the real slowdown will happen on Wednesday. Just saying&#8230; it has happened before. :)</p><p>Talk soon,</p><p><strong>Nelson</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Nelson Lopes [EN] is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The reason I use an RFID-blocking wallet]]></title><description><![CDATA[Did you know that a malicious person can easily steal your money by simply holding a payment terminal close to your pocket or wallet?]]></description><link>https://newsletter.nelsonlopes.net/p/the-reason-i-use-an-rfid-blocking</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/the-reason-i-use-an-rfid-blocking</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Tue, 05 Aug 2025 08:00:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!BhFr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hello again :)</p><p>Nowadays, we increasingly have less need to carry a physical wallet. For example, in Portugal, the gov.id app (<a href="https://apps.apple.com/pt/app/gov-pt/id1384884826">iOS</a>, <a href="https://play.google.com/store/apps/details?id=id.gov.pt&amp;hl=pt">Android</a>) already allows users to legally present their citizen card, driver&#8217;s license, vehicle registration certificate, car insurance, among other documents, meaning there&#8217;s no longer a need to carry them physically.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Nelson Lopes is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>NFC technology, used in banking apps, has long allowed for contactless payments without physical cards. For instance, also in Portugal, the MBWay app enables payments not only via NFC but also through QR code scanning, which greatly simplifies the payment process and reduces - or even eliminates - the need to carry physical bank cards.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BhFr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BhFr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BhFr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BhFr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BhFr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BhFr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1191162,&quot;alt&quot;:&quot;A regular wallets, and completely unprotected from digital pickpockets.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://lopesnelson.substack.com/i/170022533?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A regular wallets, and completely unprotected from digital pickpockets." title="A regular wallets, and completely unprotected from digital pickpockets." srcset="https://substackcdn.com/image/fetch/$s_!BhFr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BhFr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BhFr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BhFr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc4ef0da6-a03b-417c-ad9a-73c413cee669_5472x3648.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Regular wallets are completely unprotected from digital pickpockets.</figcaption></figure></div><p>Still, most people continue to carry their physical ID and bank cards - either because they&#8217;re not comfortable with the technology (they don&#8217;t know how it works or are afraid of making mistakes), don&#8217;t trust it yet, haven&#8217;t taken the time to test it, or simply don&#8217;t want to. A friend of mine once said he didn&#8217;t use MBWay because it drains his smartphone battery &#128558;</p><p>That said, it&#8217;s important to be aware that contactless cards don&#8217;t need to be inserted into a payment terminal to complete a transaction - just bringing them close is enough. This also means that a malicious person could approach your pocket or wallet with a payment device in a crowded street or public place and charge you without your consent.</p><p>PIN entry is only required for payments above a certain amount, so any charge below that limit will go through without issue.</p><p>The same risk exists if you keep NFC enabled on your smartphone and your banking apps are configured for payments. <strong>You should always disable NFC when you&#8217;re not using it</strong>.</p><p>Additionally, it&#8217;s important to know that access cards to private buildings can be cloned very easily using tools that are freely available online - like the <a href="https://flipperzero.one/">Flipper Zero</a>. Once a card is scanned, its data can be stored on the Flipper Zero and:</p><ul><li><p>Replayed by holding the Flipper Zero close to an access reader, unlocking a door, safe, garage, etc. that was originally restricted to the access card;</p></li><li><p>Or cloned onto a blank smart card, creating a duplicate of the original (which is much less suspicious than carrying around a Flipper Zero).</p></li></ul><p>Because of this, <strong>I strongly recommend using RFID-blocking wallets</strong> so that all cards inside are secure from these types of attacks. These wallets are available both online and in physical stores.</p><p><strong>Don&#8217;t forget to test your wallet</strong> to make sure the RFID-blocking actually works. To do this, try making a payment while your bank card is inside the wallet. If all goes well, nothing will happen - you&#8217;ll need to remove the card in order to complete the transaction.</p><p>If you don&#8217;t have one of these wallets yet, don&#8217;t wait. Get yours today!</p><p>Thanks, and see you soon,<br><strong>Nelson</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Nelson Lopes is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The beginning]]></title><description><![CDATA[As a computer enthusiast and Director of Information Systems, my daily work revolves around technology. Beyond managing teams and departments, I&#8217;m involved in various areas such as networks, cloud, systems administration, software engineering, ERP, RPA, VoIP, cybersecurity, and more.]]></description><link>https://newsletter.nelsonlopes.net/p/the-beginning</link><guid isPermaLink="false">https://newsletter.nelsonlopes.net/p/the-beginning</guid><dc:creator><![CDATA[Nelson Lopes]]></dc:creator><pubDate>Sun, 03 Aug 2025 15:48:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mTWO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Hello :)</strong></p><p>Welcome to my Substack.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mTWO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mTWO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mTWO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mTWO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mTWO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mTWO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg" width="1456" height="959" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:959,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:436493,&quot;alt&quot;:&quot;Every journey starts with a blank page - just like this Substack.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://lopesnelson.substack.com/i/170009323?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Every journey starts with a blank page - just like this Substack." title="Every journey starts with a blank page - just like this Substack." srcset="https://substackcdn.com/image/fetch/$s_!mTWO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mTWO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mTWO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mTWO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F767609e5-a98e-4598-84b0-e67bd6c7aedf_5184x3416.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Every journey starts with a blank page - just like this Substack.</figcaption></figure></div><p>In this first post, I&#8217;d like to welcome you and share a bit about what you can expect to find here.</p><p>As a computer enthusiast and Director of Information Systems, my daily work revolves around technology. Beyond managing teams and departments, I&#8217;m involved in various areas such as networks, cloud, systems administration, software engineering, ERP, RPA, VoIP, cybersecurity, and more.</p><p>Outside of work, I enjoy spending time with my family, reading, running, going to the beach, and - of course - exploring technology for personal curiosity.</p><p>I hold several certifications, including CISSP, ITIL, PMP, and C|EH. I&#8217;m also a member of the Portuguese Order of Engineers, PMI, PMI Portugal, among others.</p><p>I live in Porto, Portugal, and I&#8217;m the proud father of a little girl - and of <em>Biscoito</em> (Cookie), our family cat.</p><p>On this Substack, I&#8217;ll be sharing some of my experience, with a special focus on tech updates, cybersecurity, service management (ITSM), project management, productivity, and related topics.</p><p>If you want to know more about me, you can visit <a href="https://nelsonlopes.net/about">this</a> page.</p><p>Thanks for reading,<br><strong>Nelson</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://newsletter.nelsonlopes.net/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>